Cross-Site Scripting Vulnerability in Lexiglot by Just Another Hacker
CVE-2014-8944
5.4MEDIUM
What is CVE-2014-8944?
Lexiglot, a plugin for WordPress, is susceptible to cross-site scripting (XSS) attacks. These vulnerabilities allow an attacker to inject malicious scripts via the username field or to exploit certain parameters in the admin interface. Specifically, the parameters 'install_name', 'intro_message', and 'new_file_content' are points of injection. This can lead to both reflected and stored XSS, potentially compromising user data integrity and impacting the overall security of web applications utilizing this plugin.