nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-18536 CVE-2017-18536
MEDIUMNuclei
WordPress Stop User Enumeration <=1.3.7 - Cross-Site Scripting
Record summary
CVE-2017-18536 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
The stop-user-enumeration plugin before 1.3.8 for WordPress has XSS.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryMEDIUMWordPress Stop User Enumeration <=1.3.7 - Cross-Site ScriptingCVSS 6.1
WordPress Stop User Enumeration 1.3.7 and earlier are vulnerable to unauthenticated reflected cross-site scripting.
Impact
This vulnerability allows remote attackers to execute arbitrary script or HTML code in the context of the victim's browser, potentially leading to session hijacking, phishing attacks, or defacement of the affected website.
Remediation
Update to the latest version of the WordPress Stop User Enumeration plugin or apply the provided patch to fix the vulnerability.
WeaknessesCWE-79
Authorsdaffainfo
Template tagscve2017cvewpscanwordpressxsswp-pluginfullworksvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:fullworks:stop_user_enumeration:*:*:*:*:*:wordpress:*:*
https://wpscan.com/vulnerability/956cc5fd-af06-43ac-aa85-46b468c73501 https://wordpress.org/plugins/stop-user-enumeration/#developers https://nvd.nist.gov/vuln/detail/CVE-2017-18536 https://github.com/ARPSyndicate/kenzer-templates
Source: ProjectDiscovery
References
2wordpress.org
https://wordpress.org/plugins/stop-user-enumeration