S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 16, 2024

CVE-2017-18542 Scanner

CVE-2017-18542 scanner - Cross-Site Scripting (XSS) vulnerability in Zendesk Help Center plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.3k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2017-18542
6.1
CVSS

The zendesk-help-center plugin before 1.0.5 for WordPress has multiple XSS issues.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

Introduction

Zendesk Help Center plugin for WordPress is an exceptional tool designed to seamlessly integrate your website's support system with your Zendesk Help Center. Widely adopted by businesses and organizations that utilize WordPress as their platform, this plugin empowers users to access their help center articles, community posts, and other essential information directly from their own website without the need for users to navigate to an external web page.

Vulnerability Overview

A critical security vulnerability, identified by the CVE code CVE-2017-18542, has been discovered in this widely-used plugin. The vulnerability falls under the Cross-Site Scripting (XSS) category, which, if exploited, could put users of the Zendesk Help Center plugin for WordPress at risk. With a successful XSS attack, malicious actors can perform unauthorized actions on behalf of users and intercept sensitive user information.

While there have been no publicized actual instances of attackers exploiting this vulnerability, it's important to consider the potential threats and act proactively before any damage is done to your website and sensitive user data.

Vulnerability Details

The CVE-2017-18542 vulnerability affects the Zendesk Help Center plugin versions before 1.0.5 for WordPress. This specific XSS vulnerability arises from multiple issues within the plugin, making it possible for attackers to inject malicious scripts into targeted web pages via crafted inputs.

If successfully exploited, attackers could potentially:

  • Access sensitive user data and credentials
  • Impersonate users and perform malicious actions
  • Compromise the integrity of your website
Solution Advice

To protect your website and users from the CVE-2017-18542 vulnerability in Zendesk Help Center plugin for WordPress, the following measures should be taken:

  • Update your plugin to version 1.0.5 or later
  • Regularly search for and apply security patches provided by Zendesk and WordPress
  • Review your website's security configuration and settings
  • Consider implementing a Content Security Policy (CSP) to further protect your website from XSS vulnerabilities

By adhering to these measures, you can significantly reduce the risks associated with the CVE-2017-18542 vulnerability and ensure the security of your website and its users.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2017-18542 scanner - Cross-Site Scripting (XSS) vulnerability in Zendesk Help Center plugin for WordPress | S4E