Skip to main content

WordPress Plugin Vulnerability

A popular WordPress plugin has been found to be vulnerable to cross site scripting (XSS) and PHP injection attacks.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

A popular WordPress plugin has been found to be vulnerable to cross site scripting (XSS) and PHP injection attacks.

Threat details

The Splashing Images plugin has been identified as having two vulnerabilities. The first, CVE-2018-6195, could allow an authenticated attacker to inject PHP code into the current WordPress instance using specially crafted URLs. Depending on the active classes, this could lead to file deletion or remote code execution.

The second vulnerability, CVE-2018-6194, allows an attacker to inject client-side scripts into a WordPress page. These pages could then be seen by other users, potentially compromising them as well. An attacker could also bypass access controls to access other areas of the web application.

For further information please see:


Remediation steps

Type Step
This vulnerability has been patched in version 2.1.1 of WordPress. It is recommended that users apply this update immediately.

Last edited: 17 February 2020 12:57 pm