Cross-Site Scripting Vulnerability in SoundCloud Is Gold Plugin for WordPress
CVE-2012-6624
Currently unrated
What is CVE-2012-6624?
The SoundCloud Is Gold plugin version 2.1 for WordPress contains a cross-site scripting (XSS) vulnerability. Attackers can exploit this flaw by injecting malicious web scripts or HTML through the 'width' parameter during a request to the wp-admin/admin-ajax.php endpoint. This can lead to unauthorized data access or compromise of user sessions, making it crucial for users of the affected plugin to take remedial actions.