Vulnerability Description
The leenkme plugin before 2.6.0 for WordPress has stored XSS via facebook_message, facebook_linkname, facebook_caption, facebook_description, default_image, or _wp_http_referer.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Leenk | Leenk.Me | < 2.6.0 |
Related Weaknesses (CWE)
References
- https://wordpress.org/plugins/leenkme/#developersRelease Notes
- https://wpvulndb.com/vulnerabilities/8457Third Party Advisory
- https://www.openwall.com/lists/oss-security/2016/04/16/4ExploitMailing ListThird Party Advisory
- https://wordpress.org/plugins/leenkme/#developersRelease Notes
- https://wpvulndb.com/vulnerabilities/8457Third Party Advisory
- https://www.openwall.com/lists/oss-security/2016/04/16/4ExploitMailing ListThird Party Advisory
FAQ
What is CVE-2016-10988?
CVE-2016-10988 is a vulnerability with a CVSS score of 6.1 (MEDIUM). The leenkme plugin before 2.6.0 for WordPress has stored XSS via facebook_message, facebook_linkname, facebook_caption, facebook_description, default_image, or _wp_http_referer.
How severe is CVE-2016-10988?
CVE-2016-10988 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-10988?
Check the references section above for vendor advisories and patch information. Affected products include: Leenk Leenk.Me.