Cross-Site Scripting in Compfight Plugin for WordPress
CVE-2014-5202

Currently unrated

Key Information:

Vendor
Wordpress
Status
Vendor
CVE Published:
12 August 2014

Summary

The Compfight plugin version 1.4 for WordPress contains a cross-site scripting (XSS) vulnerability in the compfight-search.php file. This flaw allows remote authenticated users to inject arbitrary web scripts or HTML through the search-value parameter. Successful exploitation can lead to unauthorized actions or information disclosure, making it crucial for site administrators to ensure their plugins are updated to secure versions.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.