CVE-2017-18598
18Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 1.9%
exploitation probability
1.9%top 22% of all CVEs
observed exploitation
nono source reports it
The Qards plugin through 2017-10-11 for WordPress has XSS via a remote document specified in the url parameter to html2canvasproxy.php.
Affected products
n/a · n/a