S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2018-5316 Scanner

CVE-2018-5316 scanner - Cross-Site Scripting (XSS) vulnerability in SagePay Server Gateway for WooCommerce plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.1k
Times Used
continuous scan runs
3.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2018-5316
6.1
CVSS

The "SagePay Server Gateway for WooCommerce" plugin before 1.0.9 for WordPress has XSS via the includes/pages/redirect.php page parameter.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

The SagePay Server Gateway for WooCommerce is a plugin designed to ensure secure payment transactions and enhance the user experience of WordPress users. This plugin works by routing the payment process to a separate SagePay server, reducing the risk of payment fraud and unauthorised access to sensitive information. The plugin provides an efficient and reliable payment gateway for ecommerce websites, allowing users to shop and pay in a secure environment. This plugin is essential for online retailers looking for a fast and secure payment system to manage both credit card and debit card transactions.

One vulnerability that has been detected in this product is CVE-2018-5316. This XSS (Cross-site Scripting) vulnerability can be exploited by injecting malicious scripts into the plugin's redirect.php page parameter. This vulnerability allows cyber attackers to inject harmful code that could potentially compromise customer data and personal information, allowing them to steal sensitive data and gain access to company systems.

When exploited, this vulnerability can lead to various consequences, including data breaches, stolen customer information, loss of revenue, and damaged company reputation. Attackers can use the compromised system to conduct further malicious activity, such as launching phishing attacks, engaging in identity theft, or selling stolen data on the dark web. This could result in significant financial losses and harm to the company's reputation.

It is essential to stay informed about the latest cybersecurity vulnerabilities and cyber threats. The pro features of s4e.io provide users with the ability to quickly and easily learn about vulnerabilities in their digital assets. With s4e.io, users can gain access to a platform with a comprehensive database of known vulnerabilities that allows users to test their systems for known vulnerabilities. By taking advantage of this platform, users can proactively protect their systems against cyber threats and stay one step ahead of attackers.

 

REFERENCES

Solution Advice

To protect against this vulnerability, several precautions can be taken, including:

  • Regularly updating the plugin to its latest version
  • Filtering input parameters through validation and sanitization
  • Applying input validation rules that ensure that user input is safe
  • Avoiding the use of user input in dynamic HTML or JavaScript content
  • Educating users on how to identify and report suspicious activity

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.