Record summary

CVE-2019-17233 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows HTML content injection.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Dec 30, 2022 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress Ultimate FAQs <= 1.8.24 – Unauthenticated HTML Content InjectionCVSS 6.1

Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows HTML content injection.

Impact

Unauthenticated attackers can inject arbitrary HTML content through FAQ imports, potentially embedding malicious links or scripts that will be displayed to site visitors.

Remediation

Update the Ultimate FAQs plugin to version 1.8.25 or later.

Authorsdaffainfo
Template tagscvecve2019wordpresswp-pluginwpultimate-faqsintrusivevkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:etoilewebdesign:ultimate_faq:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

4