Description
An issue was discovered in the MULTIDOTS Advance Search for WooCommerce plugin 1.0.9 and earlier for WordPress. This plugin is vulnerable to a stored Cross-site scripting (XSS) vulnerability. A non-authenticated user can save the plugin settings and inject malicious JavaScript code in the Custom CSS textarea field, which will be loaded on every site page.
Published: 2018-06-01
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2018-3517 An issue was discovered in the MULTIDOTS Advance Search for WooCommerce plugin 1.0.9 and earlier for WordPress. This plugin is vulnerable to a stored Cross-site scripting (XSS) vulnerability. A non-authenticated user can save the plugin settings and inject malicious JavaScript code in the Custom CSS textarea field, which will be loaded on every site page.
History

No history.

Subscriptions

Multidots Advance Search For Woocommerce
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T08:10:14.709Z

Reserved: 2018-05-26T00:00:00.000Z

Link: CVE-2018-11486

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-06-01T15:29:00.407

Modified: 2024-11-21T03:43:27.857

Link: CVE-2018-11486

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses