Cross-Site Scripting Vulnerability in Banner Effect Header Plugin for WordPress
CVE-2015-1384

Currently unrated

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
3 February 2015

Summary

The Banner Effect Header plugin for WordPress contains a Cross-Site Scripting (XSS) weakness that enables remote attackers to execute arbitrary scripts or HTML by manipulating the 'banner_effect_divid' parameter in the options page accessed through the wp-admin interface. This allows unauthorized actors to potentially compromise the security of the affected installations.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.