CVE-2017-17093 is a medium-severity cross-site scripting (XSS) vulnerability affecting WordPress versions prior to 4.9.1, specifically within the wp-includes/general-template.php file. Attackers could exploit this by manipulating the 'lang' attribute of an HTML element via a site's language setting. The CVSS score is 5.4, indicating a low attack complexity and privilege requirement, but requiring user interaction for a limited impact on confidentiality and integrity. There is no evidence of active exploitation, nor are there publicly available exploits in Metasploit or ExploitDB, and it has received no community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.9.1CPE matchmatch criteria | cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.