CVE-2018-1002001
MEDIUMWordPress Arigato Autoresponder & Newsletter <v2.5.1.8 - XSS
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-1002001. PoCs published by Larry W. Cashdollar.
AI-analyzed exploit summary The document describes multiple vulnerabilities (SQLi and XSS) in the WordPress plugin Arigato Autoresponder and Newsletter v2.5, including a blind SQL injection via the 'del_ids' parameter and nine reflected XSS vulnerabilities. It provides details on the vulnerable code lines and includes an example of using sqlmap to exploit the SQL injection.
Description
There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit.
Exploits (1)
The document describes multiple vulnerabilities (SQLi and XSS) in the WordPress plugin Arigato Autoresponder and Newsletter v2.5, including a blind SQL injection via the 'del_ids' parameter and nine reflected XSS vulnerabilities. It provides details on the vulnerable code lines and includes an example of using sqlmap to exploit the SQL injection.
References (3)
Scores
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N