Cross-Site Scripting Vulnerability in Another WordPress Classifieds Plugin by WordPress
CVE-2014-10012
Currently unrated
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 13 January 2015
Summary
The Another WordPress Classifieds Plugin contains a cross-site scripting (XSS) vulnerability that can be exploited by remote attackers. By manipulating the query string in a URL directed at the plugin's default URI, attackers can inject arbitrary web scripts or HTML. This may result in unauthorized access to sensitive information or interaction with the user at the client's end, making it critical for users to implement the latest security measures to mitigate this risk.
References
Timeline
Vulnerability published
Vulnerability Reserved