Cross-Site Scripting Vulnerability in Pods Plugin for WordPress
CVE-2014-7956
Currently unrated
Summary
The Pods plugin for WordPress is susceptible to a Cross-Site Scripting (XSS) vulnerability, allowing remote attackers to exploit the id parameter in an edit action on the pods page within the admin interface. By crafting a specially crafted request, an attacker can inject arbitrary web scripts or HTML, which could be executed in the context of a user’s session. The vulnerability affects versions of the Pods plugin prior to 2.5, making it critical for users to update their installations to maintain security.
References
Timeline
Vulnerability published
Vulnerability Reserved