Cross-Site Scripting Flaw in WhyDoWork AdSense Plugin for WordPress
CVE-2014-9100

Currently unrated

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
26 November 2014

Summary

A Cross-Site Scripting (XSS) vulnerability exists in the WhyDoWork AdSense plugin version 1.2 for WordPress. This issue allows remote attackers to inject arbitrary web scripts or HTML into the site via the 'idcode' parameter on the whydowork_adsense page, specifically affecting wp-admin/options-general.php. Exploitation of this vulnerability could lead to unauthorized actions on behalf of users or the exposure of sensitive information.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.