PT-2019-8479 · WordPress · Wordpress Invite-Anyone Plugin

Published

2019-08-16

·

Updated

2019-08-21

·

CVE-2017-18545

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions WordPress invite-anyone plugin versions prior to 1.3.16
Description The issue arises from incorrect escaping of untrusted input in both the Dashboard and front-end of the WordPress invite-anyone plugin.
Recommendations For versions prior to 1.3.16, update to version 1.3.16 or later to resolve the issue.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-18545

Affected Products

Wordpress Invite-Anyone Plugin