VYPR
Medium severity6.1NVD Advisory· Published Sep 10, 2019· Updated Jun 17, 2026

CVE-2017-18598

CVE-2017-18598

Description

The Qards plugin through 2017-10-11 for WordPress has XSS via a remote document specified in the url parameter to html2canvasproxy.php.

Affected products

3
  • cpe:2.3:a:designmodo:qards:*:*:*:*:*:wordpress:*:*
    Range: <=2017-10-11
  • WordPress/Qards plugindescription
  • WordPress/Qardsllm-create
    Range: <=2017-10-11

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.