Cross-Site Scripting Vulnerabilities in Media File Renamer Plugin for WordPress
CVE-2014-2040

Currently unrated

Key Information:

Vendor

Wordpress

Vendor
CVE Published:
3 March 2014

What is CVE-2014-2040?

The Media File Renamer plugin for WordPress contains multiple cross-site scripting (XSS) vulnerabilities in its callback functions, specifically in mfrh_class.settings-api.php. Remote authenticated users who have permissions to add or edit media can exploit these vulnerabilities to inject arbitrary web scripts or HTML. This can be achieved through unspecified parameters, such as the title of uploaded files, potentially leading to unauthorized actions or data exposure on affected WordPress sites.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.