Cross-Site Scripting Vulnerability in EWWW Image Optimizer for WordPress
CVE-2014-6243

Currently unrated

Key Information:

Vendor

Wordpress

Vendor
CVE Published:
10 October 2014

What is CVE-2014-6243?

The EWWW Image Optimizer plugin for WordPress is susceptible to cross-site scripting (XSS) attacks. This vulnerability permits unauthorized attackers to inject arbitrary web scripts or HTML into the website through the 'error' parameter in the ewww-image-optimizer.php page when accessed via wp-admin/options-general.php. The flaw in error handling can lead to the execution of malicious code, compromising the integrity and security of the affected WordPress site.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.