CVE-2018-1000508 describes a Cross-Site Scripting (XSS) vulnerability in WP ULike versions 2.8.1 and 3.1, affecting the settings screen of the plugin. This medium-severity vulnerability (CVSS 4.8) requires administrator interaction, as an admin must visit the logs page for the attack to succeed, potentially allowing unauthorized users to perform actions with administrative privileges. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE, which was patched in version 3.2.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.8.1CPE matchmatch criteria | cpe:2.3:a:wpulike:ulike:2.8.1:*:*:*:*:wordpress:*:* | ||
3.1CPE matchmatch criteria | cpe:2.3:a:wpulike:ulike:3.1:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.