Refine your search

2 vulnerabilities found for WP Retina 2x by Jordy Meow

CVE-2018-0511 (GCVE-0-2018-0511)
Vulnerability from cvelistv5
Published
2018-02-01 14:00
Modified
2024-08-05 03:28
Severity ?
CWE
  • Cross-site scripting
Summary
Cross-site scripting vulnerability in WP Retina 2x prior to version 5.2.2 allows an attacker to inject arbitrary web script or HTML via unspecified vectors.
References
Impacted products
Vendor Product Version
Jordy Meow WP Retina 2x Version: prior to version 5.2.2
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-05T03:28:10.649Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "x_refsource_CONFIRM",
              "x_transferred"
            ],
            "url": "https://plugins.trac.wordpress.org/changeset/1802137/#file1"
          },
          {
            "name": "JVN#30636823",
            "tags": [
              "third-party-advisory",
              "x_refsource_JVN",
              "x_transferred"
            ],
            "url": "https://jvn.jp/en/jp/JVN30636823/index.html"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "WP Retina 2x",
          "vendor": "Jordy Meow",
          "versions": [
            {
              "status": "affected",
              "version": "prior to version 5.2.2"
            }
          ]
        }
      ],
      "datePublic": "2018-01-30T00:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "value": "Cross-site scripting vulnerability in WP Retina 2x prior to version 5.2.2 allows an attacker to inject arbitrary web script or HTML via unspecified vectors."
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "description": "Cross-site scripting",
              "lang": "en",
              "type": "text"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2018-02-01T13:57:01.000Z",
        "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
        "shortName": "jpcert"
      },
      "references": [
        {
          "tags": [
            "x_refsource_CONFIRM"
          ],
          "url": "https://plugins.trac.wordpress.org/changeset/1802137/#file1"
        },
        {
          "name": "JVN#30636823",
          "tags": [
            "third-party-advisory",
            "x_refsource_JVN"
          ],
          "url": "https://jvn.jp/en/jp/JVN30636823/index.html"
        }
      ],
      "x_legacyV4Record": {
        "CVE_data_meta": {
          "ASSIGNER": "vultures@jpcert.or.jp",
          "ID": "CVE-2018-0511",
          "STATE": "PUBLIC"
        },
        "affects": {
          "vendor": {
            "vendor_data": [
              {
                "product": {
                  "product_data": [
                    {
                      "product_name": "WP Retina 2x",
                      "version": {
                        "version_data": [
                          {
                            "version_value": "prior to version 5.2.2"
                          }
                        ]
                      }
                    }
                  ]
                },
                "vendor_name": "Jordy Meow"
              }
            ]
          }
        },
        "data_format": "MITRE",
        "data_type": "CVE",
        "data_version": "4.0",
        "description": {
          "description_data": [
            {
              "lang": "eng",
              "value": "Cross-site scripting vulnerability in WP Retina 2x prior to version 5.2.2 allows an attacker to inject arbitrary web script or HTML via unspecified vectors."
            }
          ]
        },
        "problemtype": {
          "problemtype_data": [
            {
              "description": [
                {
                  "lang": "eng",
                  "value": "Cross-site scripting"
                }
              ]
            }
          ]
        },
        "references": {
          "reference_data": [
            {
              "name": "https://plugins.trac.wordpress.org/changeset/1802137/#file1",
              "refsource": "CONFIRM",
              "url": "https://plugins.trac.wordpress.org/changeset/1802137/#file1"
            },
            {
              "name": "JVN#30636823",
              "refsource": "JVN",
              "url": "https://jvn.jp/en/jp/JVN30636823/index.html"
            }
          ]
        }
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
    "assignerShortName": "jpcert",
    "cveId": "CVE-2018-0511",
    "datePublished": "2018-02-01T14:00:00.000Z",
    "dateReserved": "2017-11-27T00:00:00.000Z",
    "dateUpdated": "2024-08-05T03:28:10.649Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}

jvndb-2018-000005
Vulnerability from jvndb
Published
2018-01-30 12:30
Modified
2018-04-11 11:53
Severity ?
Summary
WordPress plugin "WP Retina 2x" vulnerable to cross-site scripting
Details
The WordPress plugin "WP Retina 2x" contains a reflected cross-site scripting vulnerability (CWE-79). Chris Liu reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
Impacted products
Show details on JVN DB website


{
  "@rdf:about": "https://jvndb.jvn.jp/en/contents/2018/JVNDB-2018-000005.html",
  "dc:date": "2018-04-11T11:53+09:00",
  "dcterms:issued": "2018-01-30T12:30+09:00",
  "dcterms:modified": "2018-04-11T11:53+09:00",
  "description": "The WordPress plugin \"WP Retina 2x\" contains a reflected cross-site scripting vulnerability (CWE-79).\r\n\r\nChris Liu reported this vulnerability to IPA.\r\nJPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.",
  "link": "https://jvndb.jvn.jp/en/contents/2018/JVNDB-2018-000005.html",
  "sec:cpe": {
    "#text": "cpe:/a:jordy_meow:wp_retina_2x",
    "@product": "WP Retina 2x",
    "@vendor": "Jordy Meow",
    "@version": "2.2"
  },
  "sec:cvss": [
    {
      "@score": "2.6",
      "@severity": "Low",
      "@type": "Base",
      "@vector": "AV:N/AC:H/Au:N/C:N/I:P/A:N",
      "@version": "2.0"
    },
    {
      "@score": "6.1",
      "@severity": "Medium",
      "@type": "Base",
      "@vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
      "@version": "3.0"
    }
  ],
  "sec:identifier": "JVNDB-2018-000005",
  "sec:references": [
    {
      "#text": "http://jvn.jp/en/jp/JVN30636823/index.html",
      "@id": "JVN#30636823",
      "@source": "JVN"
    },
    {
      "#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-0511",
      "@id": "CVE-2018-0511",
      "@source": "CVE"
    },
    {
      "#text": "https://nvd.nist.gov/vuln/detail/CVE-2018-0511",
      "@id": "CVE-2018-0511",
      "@source": "NVD"
    },
    {
      "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
      "@id": "CWE-79",
      "@title": "Cross-site Scripting(CWE-79)"
    }
  ],
  "title": "WordPress plugin \"WP Retina 2x\" vulnerable to cross-site scripting"
}