CVE-2018-1002008: Kibokolabs Arigato Autoresponder And Newsletter

Medium severity, CVSS 4.8. EPSS: 2.6% chance of exploitation in the next 30 days.

There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit. There is an XSS vulnerability in list-user.html.php:4: via GET request offset variable.

Affected products

  • Kibokolabs Arigato Autoresponder And Newsletter: version 2.5.1.8 only

Published 2018-12-03. Last modified 2026-06-17.