Cross-Site Scripting Vulnerability in WP Consultant Plugin for WordPress
CVE-2014-4582
Currently unrated
What is CVE-2014-4582?
A Cross-Site Scripting (XSS) flaw exists in the WP Consultant plugin for WordPress, specifically within the admin_show_dialogs.php script. This vulnerability enables attackers to inject arbitrary web scripts or HTML into the application through the 'dialog_id' parameter. By exploiting this weakness, attackers can execute malicious scripts within the context of the user's session, potentially compromising sensitive information and user interactions.