Cross-Site Scripting Vulnerability in Social Connect Plugin by WordPress
CVE-2014-4551

Currently unrated

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
2 July 2014

Summary

The Social Connect plugin for WordPress contains a vulnerability that allows attackers to exploit the diagnostics/test.php script. This allows remote attackers to inject arbitrary web scripts or HTML via a malicious testing parameter, potentially compromising the integrity of the website. Users of versions 1.0.4 and earlier are at risk, making it essential for admins to update or secure their installations to prevent such attacks.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.