Lucene search

K
cvelistMitreCVELIST:CVE-2018-6357
HistoryJan 27, 2018 - 5:00 p.m.

CVE-2018-6357

2018-01-2717:00:00
mitre
www.cve.org
3
cve-2018-6357
acurax-social-media-widget
function.php
csrf
recordsarray parameter
wp-admin/admin-ajax.php
xss

AI Score

8.8

Confidence

High

EPSS

0.001

Percentile

49.9%

The acx_asmw_saveorder_callback function in function.php in the acurax-social-media-widget plugin before 3.2.6 for WordPress has CSRF via the recordsArray parameter to wp-admin/admin-ajax.php, with resultant social_widget_icon_array_order XSS.

AI Score

8.8

Confidence

High

EPSS

0.001

Percentile

49.9%

Related for CVELIST:CVE-2018-6357