Cross-Site Scripting Vulnerabilities in Swipe Checkout Plugin for WordPress
CVE-2014-4559

6.1MEDIUM

Key Information:

Vendor

Wordpress

Vendor
CVE Published:
27 December 2019

What is CVE-2014-4559?

Multiple cross-site scripting vulnerabilities exist in the Swipe Checkout for WP e-Commerce plugin, specifically in the test-plugin.php file. Attackers can exploit these vulnerabilities by injecting arbitrary web scripts or HTML through vital parameters including api_key, payment_page_url, merchant_id, api_url, and currency. This can lead to malicious content being executed within the context of the affected user's session, potentially compromising sensitive information and user interaction.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.