Vulnerability Description
process_forms in the WPML (aka sitepress-multilingual-cms) plugin through 3.6.3 for WordPress has XSS via any locale_file_name_ parameter (such as locale_file_name_en) in an authenticated theme-localization.php request to wp-admin/admin.php.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Wpml | Wpml | >= 1.3.3, <= 3.6.3 |
Related Weaknesses (CWE)
References
- https://0x62626262.wordpress.com/2018/10/08/sitepress-multilingual-cms-plugin-unExploitThird Party Advisory
- https://0x62626262.wordpress.com/2018/10/08/sitepress-multilingual-cms-plugin-unExploitThird Party Advisory
FAQ
What is CVE-2018-18069?
CVE-2018-18069 is a vulnerability with a CVSS score of 6.1 (MEDIUM). process_forms in the WPML (aka sitepress-multilingual-cms) plugin through 3.6.3 for WordPress has XSS via any locale_file_name_ parameter (such as locale_file_name_en) in an authenticated theme-locali...
How severe is CVE-2018-18069?
CVE-2018-18069 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-18069?
Check the references section above for vendor advisories and patch information. Affected products include: Wpml Wpml.