blog.nintechnet.com
https://blog.nintechnet.com/unauthenticated-options-import-vulnerability-in-wordpress-ultimate-faq-plugin CVE-2019-17233
MEDIUMNuclei
etoilewebdesign ultimate_faq Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Record summary
CVE-2019-17233 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows HTML content injection.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Dec 30, 2022 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
ultimate_faqBrowse etoilewebdesign / ultimate_faq | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryMEDIUMWordPress Ultimate FAQs <= 1.8.24 – Unauthenticated HTML Content InjectionCVSS 6.1
Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows HTML content injection.
Impact
Unauthenticated attackers can inject arbitrary HTML content through FAQ imports, potentially embedding malicious links or scripts that will be displayed to site visitors.
Remediation
Update the Ultimate FAQs plugin to version 1.8.25 or later.
Authorsdaffainfo
Template tagscvecve2019wordpresswp-pluginwpultimate-faqsintrusivevkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:etoilewebdesign:ultimate_faq:*:*:*:*:*:wordpress:*:*
https://blog.nintechnet.com/unauthenticated-options-import-vulnerability-in-wordpress-ultimate-faq-plugin/ https://nvd.nist.gov/vuln/detail/CVE-2019-17233
Source: ProjectDiscovery
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-17233 wordpress.org
https://wordpress.org/plugins/ultimate-faqs wpvulndb.com
https://wpvulndb.com/vulnerabilities/9883