Cross-Site Scripting in Compfight Plugin for WordPress
CVE-2014-5202
Currently unrated
What is CVE-2014-5202?
The Compfight plugin version 1.4 for WordPress contains a cross-site scripting (XSS) vulnerability in the compfight-search.php file. This flaw allows remote authenticated users to inject arbitrary web scripts or HTML through the search-value parameter. Successful exploitation can lead to unauthorized actions or information disclosure, making it crucial for site administrators to ensure their plugins are updated to secure versions.