Cross-Site Scripting Vulnerability in Wordfence Security Plugin for WordPress
CVE-2014-4664
Currently unrated
What is CVE-2014-4664?
A cross-site scripting vulnerability exists in the Wordfence Security plugin for WordPress prior to version 5.1.4. This vulnerability allows remote attackers to inject arbitrary web scripts or HTML via a crafted 'whoisval' parameter on the WordfenceWhois page, which is processed by wp-admin/admin.php. Successful exploitation can enable attackers to execute unauthorized code in the context of the victim's browser, potentially leading to data theft, session hijacking, or website defacement.