CVE-2018-20463
45Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 13%
from disclosure to weapon
Published on NVDDec 25
VulnCheck+2095d
exploitation probability
13%top 4% of all CVEs
observed exploitation
yesVulnCheck
An issue was discovered in the JSmol2WP plugin 1.07 for WordPress. There is an arbitrary file read vulnerability via ../ directory traversal in query=php://filter/resource= in the jsmol.php query string. This can also be used for SSRF.
Affected products
n/a · n/a