Cross-Site Scripting Vulnerability in Whois Search Plugin by WordPress
CVE-2011-5193
Currently unrated
Summary
The Whois Search plugin version 1.4.2.3 for WordPress is susceptible to a cross-site scripting (XSS) vulnerability. When the WHOIS widget is enabled, this flaw allows remote attackers to inject arbitrary web scripts or HTML into the application via the 'domain' parameter passed to 'index.php'. This can lead to unauthorized actions on behalf of users and potential compromise of sensitive information.
References
Timeline
Vulnerability Reserved
Vulnerability published