Cross-Site Scripting Vulnerability in Geo Mashup Plugin for WordPress
CVE-2015-1383

Currently unrated

Key Information:

Vendor

Wordpress

Vendor
CVE Published:
2 February 2015

What is CVE-2015-1383?

The Geo Mashup plugin for WordPress contains a cross-site scripting (XSS) vulnerability that enables remote attackers to insert arbitrary web scripts or HTML through the search key in the geo search widget. This flaw, existing in versions prior to 1.8.3, can lead to unauthorized actions being executed on behalf of users, potentially compromising sensitive data or user sessions.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.