gist.github.com
https://gist.github.com/B0UG/8615df3fe83a4deca07334af783696d6 CVE-2018-10371
MEDIUM
WordPress Plugin WF Cookie Consent 1.1.3 - Cross-Site Scripting
Record summary
CVE-2018-10371 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit.
Description
An issue was discovered in the wunderfarm WF Cookie Consent plugin 1.1.3 for WordPress. A persistent cross-site scripting vulnerability has been identified in the web interface of the plugin that allows the execution of arbitrary HTML/script code to be executed in a victim's web browser via a page title.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBWordPress Plugin WF Cookie Consent 1.1.3 - Cross-Site ScriptingExploitDB exploitby B0UGNot analyzed1 file
References
5nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-10371 wordpress.org
https://wordpress.org/plugins/wf-cookie-consent wpvulndb.com
https://wpvulndb.com/vulnerabilities/9080 44585exploit
https://www.exploit-db.com/exploits/44585