Lucene search

K
cvelistMitreCVELIST:CVE-2018-11486
HistoryJun 01, 2018 - 3:00 p.m.

CVE-2018-11486

2018-06-0115:00:00
mitre
www.cve.org
3

EPSS

0.001

Percentile

35.4%

An issue was discovered in the MULTIDOTS Advance Search for WooCommerce plugin 1.0.9 and earlier for WordPress. This plugin is vulnerable to a stored Cross-site scripting (XSS) vulnerability. A non-authenticated user can save the plugin settings and inject malicious JavaScript code in the Custom CSS textarea field, which will be loaded on every site page.

EPSS

0.001

Percentile

35.4%

Related for CVELIST:CVE-2018-11486