Cross-Site Scripting Vulnerability in Banner Effect Header Plugin for WordPress
CVE-2015-1384

Currently unrated

Key Information:

Vendor

Wordpress

Vendor
CVE Published:
3 February 2015

What is CVE-2015-1384?

The Banner Effect Header plugin for WordPress contains a Cross-Site Scripting (XSS) weakness that enables remote attackers to execute arbitrary scripts or HTML by manipulating the 'banner_effect_divid' parameter in the options page accessed through the wp-admin interface. This allows unauthorized actors to potentially compromise the security of the affected installations.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
The Cyber Security Vulnerability Database.