Record summary

CVE-2017-18536 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

The stop-user-enumeration plugin before 1.3.8 for WordPress has XSS.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress Stop User Enumeration <=1.3.7 - Cross-Site ScriptingCVSS 6.1

WordPress Stop User Enumeration 1.3.7 and earlier are vulnerable to unauthenticated reflected cross-site scripting.

Impact

This vulnerability allows remote attackers to execute arbitrary script or HTML code in the context of the victim's browser, potentially leading to session hijacking, phishing attacks, or defacement of the affected website.

Remediation

Update to the latest version of the WordPress Stop User Enumeration plugin or apply the provided patch to fix the vulnerability.

WeaknessesCWE-79
Authorsdaffainfo
Template tagscve2017cvewpscanwordpressxsswp-pluginfullworksvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:fullworks:stop_user_enumeration:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

2