CVE-2018-6468

MEDIUM

flickrRSS 5.3.1 - Cross-Site Scripting via flickrRSS_id Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2018-6468. PoCs published by AntsKnows.

Description

A cross-site scripting (XSS) vulnerability in flickrRSS.php in the flickrRSS plugin 5.3.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the flickrRSS_id parameter to wp-admin/options-general.php.

References (1)

Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://github.com/AntsKnows/CVE/blob/master/WP_Plugin_Flickr-rss

Scores

CVSS v3 6.1
EPSS 0.0092
EPSS Percentile 55.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
flickrrss_project/flickrrss 5.3.1
Published Feb 06, 2018
Tracked Since Feb 18, 2026