[Japanese] | |
JVNDB-2018-000135 | |
WordPress plugin "Google XML Sitemaps" vulnerable to cross-site scripting | |
Overview | |
The WordPress plugin "Google XML Sitemaps" provided by Arne Brachhold contains a stored cross-site scripting vulnerability (CWE-79). | |
CVSS Severity (What is CVSS?) | |
CVSS V3 Severity:
Base Metrics 4.8 (Medium) [IPA Score]
CVSS V2 Severity:
Base Metrics 4.0 (Medium) [IPA Score]
| |
Affected Products | |
| |
Arne Brachhold | |
| |
Impact | |
In the case where multiple administrators manage the WordPress site with the affected plugin, an administrator with malicious intent may embed an arbitrary script into the plugin settings page. The embedded script may be executed when another administrator logs in and browses the page. | |
Solution | |
[Update the plugin] | |
Vendor Information | |
Arne Brachhold | |
CWE (What is CWE?) | |
| |
CVE (What is CVE?) | |
| |
References | |
| |
Revision History | |
|
Date Public | 2018/12/25 |
Date First Published | 2018/12/25 |
Date Last Updated | 2019/08/27 |