S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 14, 2024

CVE-2017-18516 Scanner

CVE-2017-18516 scanner - Cross-Site Scripting (XSS) vulnerability in LinkedIn plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.3k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2017-18516
6.1
CVSS

The bws-linkedin plugin before 1.0.5 for WordPress has multiple XSS issues.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

The LinkedIn plugin for WordPress is a tool utilized to connect a website with LinkedIn. It enables website owners to share their content on their LinkedIn profiles and company pages, as well as to display LinkedIn information on their pages. This can increase website traffic and visibility, and it allows visitors to learn more about the website's content creators.

One of the vulnerabilities identified in the LinkedIn plugin for WordPress is CVE-2017-18516. This cross-site scripting (XSS) vulnerability occurs when the plugin does not properly sanitize user input. As a result, an attacker can inject malicious code into the website, potentially leading to the theft of personal data or the spread of malware.

Exploitation of CVE-2017-18516 can lead to a variety of negative consequences, such as the exposure of sensitive information for both website owners and visitors. Hackers can use an XSS attack to steal login credentials, financial information, or even user session cookies. Additionally, they may inject malicious code that can install malware, modify website content, or redirect visitors to a fake website. 

In conclusion, the LinkedIn plugin for WordPress is a valuable tool for website owners to increase their visibility and build connections. However, it's important to be aware of the vulnerabilities that can arise, such as CVE-2017-18516. By taking preventive measures, website owners can protect themselves and their visitors from the negative consequences of cyberattacks. For more information on safeguarding your digital assets, check out the pro features of s4e.io. With our platform, you can easily and quickly identify vulnerabilities and risks in your digital assets, and take action to prevent them.

 

REFERENCES

Solution Advice

There are several precautions that can be taken to protect against the vulnerability. Below are some bullet points to keep in mind:

  • Update to the latest version of the LinkedIn plugin for WordPress as soon as possible.
  • Use a web application firewall (WAF) to block malicious traffic and filter out malicious code.
  • Implement strict content security policies (CSPs) to restrict the types of code that can be executed on the website.
  • Educate users on how to identify and avoid phishing attacks and other forms of social engineering.
  • Regularly monitor website activity and traffic logs for suspicious behavior or signs of compromise.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2017-18516 scanner - Cross-Site Scripting (XSS) vulnerability in LinkedIn plugin for WordPress | S4E