XSS Vulnerability in BannerMan Plugin for WordPress
CVE-2014-4845
Currently unrated
What is CVE-2014-4845?
A cross-site scripting (XSS) vulnerability exists in the BannerMan plugin version 0.2.4 for WordPress, which allows attackers to inject arbitrary web scripts or HTML. This can occur through the bannerman_background
parameter via the wp-admin/options-general.php interface. Successful exploitation of this vulnerability could enable unauthorized parties to execute malicious scripts in users' browsers, potentially leading to session hijacking or other malicious activities.