Cross-site Scripting Vulnerability in WP Plugin Manager for WordPress
CVE-2014-4593
Currently unrated
Summary
The WP Plugin Manager (wppm) plugin for WordPress contains a Cross-site Scripting (XSS) vulnerability that allows remote attackers to inject arbitrary web scripts or HTML through the 'filter' parameter in the index.php file. This flaw could potentially be exploited to execute malicious scripts in the context of a user’s session, compromising the integrity of the site and its users.
References
Timeline
Vulnerability published
Vulnerability Reserved