Cross-Site Scripting Vulnerability in WP Consultant Plugin for WordPress
CVE-2014-4582

Currently unrated

Key Information:

Vendor

Wordpress

Vendor
CVE Published:
2 July 2014

What is CVE-2014-4582?

A Cross-Site Scripting (XSS) flaw exists in the WP Consultant plugin for WordPress, specifically within the admin_show_dialogs.php script. This vulnerability enables attackers to inject arbitrary web scripts or HTML into the application through the 'dialog_id' parameter. By exploiting this weakness, attackers can execute malicious scripts within the context of the user's session, potentially compromising sensitive information and user interactions.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.