JSmol2WP <= 1.07 - Cross-Site Scripting
medium
An issue was discovered in the JSmol2WP plugin 1.07 for WordPress. A cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via the jsmol.php data parameter.
- CVSS:
- 6.1
- Affected:
- up to 1.07
- Fix:
- No patched version reported
- Disclosed:
- Jan 7, 2019
CVE-2018-20462 on NVD →
JSmol2WP <= 1.07 - Server-Side Request Forgery
high
An issue was discovered in the JSmol2WP plugin 1.07 for WordPress. There is an arbitrary file read vulnerability via ../ directory traversal in query=php://filter/resource= in the jsmol.php query string. This can also be used for SSRF.
- CVSS:
- 7.5
- Affected:
- up to 1.07
- Fix:
- No patched version reported
- Disclosed:
- Dec 25, 2018
CVE-2018-20463 on NVD →
JSmol2WP [jsmol2wp] <= 1.07 (unfixed + closed)
unknown
[en] An issue was discovered in the JSmol2WP plugin 1.07 for WordPress. A cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via the jsmol.php data parameter.
- Affected:
- up to 1.07
- Fix:
- No patched version reported
- Disclosed:
- Dec 25, 2018
CVE-2018-20462 on NVD →
JSmol2WP [jsmol2wp] <= 1.07 (unfixed + closed)
unknown
[en] An issue was discovered in the JSmol2WP plugin 1.07 for WordPress. There is an arbitrary file read vulnerability via ../ directory traversal in query=php://filter/resource= in the jsmol.php query string. This can also be used for SSRF.
- Affected:
- up to 1.07
- Fix:
- No patched version reported
- Disclosed:
- Dec 25, 2018
CVE-2018-20463 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database