Cross-site Scripting Vulnerability in Hot Files Plugin for WordPress
CVE-2014-4588
Currently unrated
What is CVE-2014-4588?
The Hot Files: File Sharing and Download Manager plugin for WordPress contains a cross-site scripting vulnerability in the tpls/editmedia.php file. This flaw allows remote attackers to inject arbitrary web scripts or HTML code via the mediaid parameter, potentially compromising the security of the affected WordPress site.