S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 14, 2024

CVE-2017-18517 Scanner

CVE-2017-18517 scanner - Cross-Site Scripting (XSS) vulnerability in Pinterest plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.9k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2017-18517
6.1
CVSS

The bws-pinterest plugin before 1.0.5 for WordPress has multiple XSS issues.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

The bws-pinterest plugin is a popular tool designed for WordPress websites to assist users in maintaining a strong presence on Pinterest. It is known for being useful in automating the sharing of website content on Pinterest boards, promoting brand recognition and driving traffic to websites. This plugin has become a staple for businesses seeking to maximize their organic reach on Pinterest. 

Unfortunately, the bws-pinterest plugin before 1.0.5 for WordPress has multiple XSS issues that have been detected, CVE-2017-18517 being among them. This particular vulnerability is caused by an improper handling of user input in an AJAX action. What this means is that a remote attacker can exploit this flaw to inject malicious scripts into the targeted website, and as a result, steal sensitive data, such as login credentials and user information. 

If the aforementioned vulnerability is exploited, it can have severe consequences. For example, it can negatively impact a website's search engine optimization (SEO) rankings and overall credibility. The attackers can leverage the XSS vulnerability to perform phishing scams, tricking users into clicking on malicious links, and leading them to phishing websites to steal their personal information. Additionally, attackers can deface the target website or even use it as a platform to launch further attacks. 

In conclusion, the bws-pinterest plugin before 1.0.5 for WordPress does come with vulnerabilities resulting in multiple XSS issues, causing great risk to users who use it. As a result, it's essential for businesses to take the necessary precautions to protect against such vulnerabilities. s4e.io offers valuable assistance to those seeking a proactive approach to cybersecurity and access to pro features. Their platform provides up-to-date information on current vulnerabilities, allowing for swift and comprehensive protection to vulnerable digital assets. Remember, when it comes to cybersecurity, prevention is better than cure.

 

REFERENCES

Solution Advice

Here are some examples of precautions that can be taken to protect against this vulnerability: 

  • Update the plugin to the latest version 
  • Install an equivalent plugin that doesn't exploit this vulnerability 
  • Utilize a Web Application Firewall (WAF) 
  • Employ Content Security Policy (CSP). 

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2017-18517 scanner - Cross-Site Scripting (XSS) vulnerability in Pinterest plugin for WordPress | S4E