CVE Feed

    Dashboard / CVE / CVE-2017-17780

    CVE-2017-17780

    The Clockwork SMS clockwork-test-message.php component has XSS via a crafted "to" parameter in a clockwork-test-message request to wp-admin/admin.php. This component code is found in the following WordPress plugins: Clockwork Free and Paid SMS Notifications 2.0.3, Two-Factor Authentication - Clockwork SMS 1.0.2, Booking Calendar - Clockwork SMS 1.0.5, Contact Form 7 - Clockwork SMS 2.3.0, Fast Secure Contact Form - Clockwork SMS 2.1.2, Formidable - Clockwork SMS 1.0.2, Gravity Forms - Clockwork SMS 2.2, and WP e-Commerce - Clockwork SMS 2.0.5.

    Published:Dec 20, 2017
    Last Modified:Apr 20, 2025
    EPS:Dec 20, 2017
    EPSS Score:0.00281
    CVSS Score:6.1

    Affected Products

    Vendor
    Mediaburst
    Product
    Booking Calendar Sms
    Vendor
    Mediaburst
    Product
    Clockwork Sms Notfications
    Vendor
    Mediaburst
    Product
    Contact Form 7 Sms
    Vendor
    Mediaburst
    Product
    Fast Secure Contact Form Sms
    Vendor
    Mediaburst
    Product
    Formidable
    Vendor
    Mediaburst
    Product
    Gravity Forms
    Vendor
    Mediaburst
    Product
    Two-factor Authentication
    Vendor
    Mediaburst
    Product
    Wp E-commerce

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High