S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 14, 2024

CVE-2017-18518 Scanner

CVE-2017-18518 scanner - Cross-Site Scripting (XSS) vulnerability in SMTP plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.8k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2017-18518
6.1
CVSS

The bws-smtp plugin before 1.1.0 for WordPress has multiple XSS issues.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

SMTP, or Simple Mail Transfer Protocol, is a plugin for WordPress designed to enable the sending of emails from the platform. The SMTP plugin is crucial for website administrators who need to send transactional emails to users, such as password resets, user registrations, and email newsletters. SMTP streamlines the process of sending emails from WordPress websites and ensures that the emails reach the intended recipient.

One vulnerability that has been detected within the SMTP plugin is CVE-2017-18518. This vulnerability is an XSS (Cross-Site Scripting) issue, meaning that it allows an attacker to inject malicious scripts into a web page viewed by another user. This vulnerability exploits a lack of input sanitization, leading to the execution of unwanted actions, including stealing user information, destroying data, or serving malware.

When exploited, the CVE-2017-18518 vulnerability can have devastating effects on a website's functionality and security. An attacker could use this vulnerability to inject malicious scripts that could, in turn, steal sensitive information, including passwords, bank details, and other personal data. An attacker could also exploit the vulnerability to hijack user accounts, redirect traffic to other malicious websites, and install malware on the user's device.

In conclusion, it is crucial to protect websites against CVE-2017-18518 and other vulnerabilities that may arise. By using the pro features of the s4e.io platform, website administrators can quickly and easily perform vulnerability scans and identify issues that need to be fixed. This way, website administrators can ensure that their digital assets are protected against malicious actors and that their users' data remains secure.

 

REFERENCES

Solution Advice

To protect against the CVE-2017-18518 vulnerability and other XSS issues, website administrators can take the following precautions:

  • Keep the SMTP plugin updated regularly
  • Limit user access to the plugin
  • Use input validation and sanitization techniques
  • Use a web application firewall (WAF) to block malicious scripts
  • Use security plugins to monitor for any suspicious activity.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2017-18518 scanner - Cross-Site Scripting (XSS) vulnerability in SMTP plugin for WordPress | S4E