XSS Vulnerability in BannerMan Plugin for WordPress
CVE-2014-4845

Currently unrated

Key Information:

Vendor
Wordpress
Status
Vendor
CVE Published:
10 July 2014

Summary

A cross-site scripting (XSS) vulnerability exists in the BannerMan plugin version 0.2.4 for WordPress, which allows attackers to inject arbitrary web scripts or HTML. This can occur through the bannerman_background parameter via the wp-admin/options-general.php interface. Successful exploitation of this vulnerability could enable unauthorized parties to execute malicious scripts in users' browsers, potentially leading to session hijacking or other malicious activities.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.