Cross-Site Scripting Vulnerability in Whois Search Plugin by WordPress
CVE-2011-5193

Currently unrated

Key Information:

Vendor
Wordpress
Status
Vendor
CVE Published:
23 September 2012

Summary

The Whois Search plugin version 1.4.2.3 for WordPress is susceptible to a cross-site scripting (XSS) vulnerability. When the WHOIS widget is enabled, this flaw allows remote attackers to inject arbitrary web scripts or HTML into the application via the 'domain' parameter passed to 'index.php'. This can lead to unauthorized actions on behalf of users and potential compromise of sensitive information.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.