Multiple XSS Vulnerabilities in WooCommerce SagePay Direct Payment Gateway Plugin
CVE-2014-4549
Currently unrated
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 2 July 2014
What is CVE-2014-4549?
The WooCommerce SagePay Direct Payment Gateway plugin contains vulnerabilities that allow remote attackers to exploit insufficient input validation, enabling them to inject arbitrary web scripts or HTML through the MD and PARes parameters. Successful exploitation could lead to malicious scripts executing in users' browsers, potentially compromising sensitive information and disrupting website functionality.