Cross-Site Scripting Vulnerability in WP-FaceThumb Plugin for WordPress
CVE-2014-4585
Currently unrated
Summary
A cross-site scripting vulnerability exists in the WP-FaceThumb plugin for WordPress, which could allow remote attackers to inject arbitrary web scripts or HTML through the ajax_url parameter in index.php. This vulnerability poses a significant risk as it could lead to unauthorized access, data theft, and further exploitation of vulnerable WordPress sites.
References
Timeline
Vulnerability published
Vulnerability Reserved