Medium severity4.8NVD Advisory· Published Jan 12, 2018· Updated Jun 17, 2026
CVE-2018-5363
CVE-2018-5363
Description
The WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[enabled_languages][en] or wpglobus_option[enabled_languages][fr] (or any other language) parameter to wp-admin/options.php.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
wpglobus/wpglobusPackagist | < 1.9.7 | 1.9.7 |
Affected products
2Patches
Vulnerability mechanics
References
4- github.com/d4wner/Vulnerabilities-Report/blob/master/wpglobus.mdnvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-gpq5-vqvx-ch9jghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2018-5363ghsaADVISORY
- wpvulndb.com/vulnerabilities/9003nvdThird Party AdvisoryVDB EntryWEB
News mentions
0No linked articles in our index yet.