CVE-2018-11709
MEDIUMNuclei
WordPress wpForo Forum <= 1.4.11 - Cross-Site Scripting
Record summary
CVE-2018-11709 has a selected CVSS score of 6.1 (medium); EIP currently links 1 curated repository PoC and 1 Nuclei template.
Proofs of concept
1Curated repository PoCs
GitHubCVE-2018-11709Curated repository PoCby yubsyStars: 112Not analyzed1 file
Nuclei templates
1ProjectDiscoveryMEDIUMWordPress wpForo Forum <= 1.4.11 - Cross-Site ScriptingCVSS 6.1
WordPress wpForo Forum plugin before 1.4.12 for WordPress allows unauthenticated reflected cross-site scripting via the URI.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary script code in the context of the affected website, potentially leading to session hijacking, defacement, or theft of sensitive information.
Remediation
Update to the latest version of the wpForo Forum plugin (1.4.11) or apply the vendor-provided patch to fix the vulnerability.
WeaknessesCWE-79
Authorsdaffainfo, s4e-io
Template tagscvecve2018wordpressxsswp-plugingvectorsvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:gvectors:wpforo_forum:*:*:*:*:*:wordpress:*:*
https://nvd.nist.gov/vuln/detail/CVE-2018-11709 https://wordpress.org/plugins/wpforo/#developers https://wpvulndb.com/vulnerabilities/9090 https://blog.dewhurstsecurity.com/2018/06/01/wp-foro-wordpress-plugin-xss-vulnerability.html https://github.com/ARPSyndicate/cvemon
Source: ProjectDiscovery
References
4blog.dewhurstsecurity.com
https://blog.dewhurstsecurity.com/2018/06/01/wp-foro-wordpress-plugin-xss-vulnerability.html nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-11709 wordpress.org
https://wordpress.org/plugins/wpforo wpvulndb.com
https://wpvulndb.com/vulnerabilities/9090