{"id":"CVE-2017-18610","details":"The magic-fields plugin before 1.7.2 for WordPress has XSS via the RCCWP_CreateCustomFieldPage.php custom-group-id parameter.","modified":"2026-04-10T03:59:02.074931Z","published":"2019-09-10T12:15:11.323Z","references":[{"type":"ADVISORY","url":"https://wordpress.org/plugins/magic-fields/#developers"},{"type":"FIX","url":"https://sumofpwn.nl/advisory/2016/cross_site_scripting_in_magic_fields_1_wordpress_plugin.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/hunk/magic-fields","events":[{"introduced":"0"},{"fixed":"8f7d34c2b5f47fba9803f98f07c8b90d3a7302db"}],"database_specific":{"versions":[{"introduced":"0"},{"fixed":"1.7.2"}]}}],"versions":["1.0","1.1","1.3","1.3-beta","1.7","1.7.1","v1.4","v1.4-beta","v1.5.2","v1.5.5","v1.5RC"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-18610.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}