3.5
CVSSv2

CVE-2018-6194

Published: 30/01/2018 Updated: 14/02/2018
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 4.8 | Impact Score: 2.7 | Exploitability Score: 1.7
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

A cross-site scripting (XSS) vulnerability in admin/partials/wp-splashing-admin-sidebar.php in the Splashing Images plugin (wp-splashing-images) prior to 2.1.1 for WordPress allows remote malicious users to inject arbitrary web script or HTML via the search parameter to wp-admin/upload.php.

Vulnerable Product Search on Vulmon Subscribe to Product

splashing images project splashing images

Exploits

WordPress Splashing Images plugin version 21 suffers from PHP object injection and cross site scripting vulnerabilities ...