Cross-Site Scripting Vulnerability in WP-FaceThumb Plugin for WordPress
CVE-2014-4585

Currently unrated

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
1 July 2014

Summary

A cross-site scripting vulnerability exists in the WP-FaceThumb plugin for WordPress, which could allow remote attackers to inject arbitrary web scripts or HTML through the ajax_url parameter in index.php. This vulnerability poses a significant risk as it could lead to unauthorized access, data theft, and further exploitation of vulnerable WordPress sites.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.