Cross-Site Scripting Vulnerability in Another WordPress Classifieds Plugin by WordPress
CVE-2014-10012

Currently unrated

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
13 January 2015

Summary

The Another WordPress Classifieds Plugin contains a cross-site scripting (XSS) vulnerability that can be exploited by remote attackers. By manipulating the query string in a URL directed at the plugin's default URI, attackers can inject arbitrary web scripts or HTML. This may result in unauthorized access to sensitive information or interaction with the user at the client's end, making it critical for users to implement the latest security measures to mitigate this risk.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.