Cross-Site Scripting Vulnerability in Pixabay Images Plugin for WordPress
CVE-2015-1366

Currently unrated

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
27 January 2015

Summary

The Pixabay Images plugin for WordPress is susceptible to a cross-site scripting (XSS) vulnerability that permits remote attackers to inject arbitrary web scripts or HTML via the image_user parameter. This security flaw was discovered prior to version 2.4 of the plugin and poses a risk of malicious exploitation, potentially leading to deceptive actions performed on behalf of the user.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.