← back
CVE-2017-18598

CVE-2017-18598

18Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 1.9%
exploitation probability
1.9%top 22% of all CVEs
observed exploitation
nono source reports it
The Qards plugin through 2017-10-11 for WordPress has XSS via a remote document specified in the url parameter to html2canvasproxy.php.
Affected products
n/a · n/a