Cross-Site Scripting Vulnerability in Pods Plugin for WordPress
CVE-2014-7956

Currently unrated

Key Information:

Vendor
Wordpress
Status
Vendor
CVE Published:
15 January 2015

Summary

The Pods plugin for WordPress is susceptible to a Cross-Site Scripting (XSS) vulnerability, allowing remote attackers to exploit the id parameter in an edit action on the pods page within the admin interface. By crafting a specially crafted request, an attacker can inject arbitrary web scripts or HTML, which could be executed in the context of a user’s session. The vulnerability affects versions of the Pods plugin prior to 2.5, making it critical for users to update their installations to maintain security.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.