CVE-2017-18510: Wpmudev Custom Sidebars

High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.

The custom-sidebars plugin before 3.1.0 for WordPress has CSRF related to set location, import actions, and export actions.

Affected products

  • Wpmudev Custom Sidebars: before 3.1.0 (fixed in 3.1.0)

Published 2019-08-14. Last modified 2026-06-17.