Cross-Site Scripting Flaw in WhyDoWork AdSense Plugin for WordPress
CVE-2014-9100
Currently unrated
Summary
A Cross-Site Scripting (XSS) vulnerability exists in the WhyDoWork AdSense plugin version 1.2 for WordPress. This issue allows remote attackers to inject arbitrary web scripts or HTML into the site via the 'idcode' parameter on the whydowork_adsense page, specifically affecting wp-admin/options-general.php. Exploitation of this vulnerability could lead to unauthorized actions on behalf of users or the exposure of sensitive information.
References
Timeline
Vulnerability Reserved
Vulnerability published