CVE-2017-18494 Scanner

Detects 'Cross-Site Scripting (XSS)' vulnerability in Custom Search plugin for WordPress affects v. before 1.36.


CVE-2017-18494 Scanner Detail

The Custom Search plugin for WordPress is a tool used to create customized search engines for WordPress websites. It allows site administrators to create fully-customized search boxes, with multiple filters and options, to help users find exactly what they are looking for on their website. This plugin is widely used by WordPress site owners to improve the user experience of their visitors.

One of the security vulnerabilities detected in this plugin is the CVE-2017-18494. This vulnerability allows attackers to inject malicious arbitrary code into the search box. This code can be executed on the website whenever a user enters a search query. This means that any website using the Custom Search plugin can be vulnerable to a Cross-Site Scripting (XSS) attack, which can lead to serious consequences.

When exploited, this vulnerability can allow the attacker to steal sensitive data such as login credentials, session tokens and other personal information of users who enter data into the search box. This can then be used for further attacks, such as identity theft or financial fraud.

When exploited, this vulnerability can allow the attacker to steal sensitive data such as login credentials, session tokens and other personal information of users who enter data into the search box. This can then be used for further attacks, such as identity theft or financial fraud.



