Cross-Site Scripting in Compfight Plugin for WordPress
CVE-2014-5202
Currently unrated
Summary
The Compfight plugin version 1.4 for WordPress contains a cross-site scripting (XSS) vulnerability in the compfight-search.php file. This flaw allows remote authenticated users to inject arbitrary web scripts or HTML through the search-value parameter. Successful exploitation can lead to unauthorized actions or information disclosure, making it crucial for site administrators to ensure their plugins are updated to secure versions.
References
Timeline
Vulnerability Reserved
Vulnerability published