Multiple Cross-Site Scripting Vulnerabilities in WP Symposium Plugin for WordPress
CVE-2014-8809

Currently unrated

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
24 December 2014

Summary

The WP Symposium plugin for WordPress has been found to contain multiple cross-site scripting (XSS) vulnerabilities that could let remote attackers inject arbitrary web scripts or HTML. These vulnerabilities can be exploited via several parameters, allowing for malicious content to be executed in the context of a user's session. Specifically, attackers can manipulate input parameters in actions such as addComment, sendMail, add_comment, and create_album, leading to potential compromise of user data or site integrity.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.