Cross-Site Scripting Vulnerability in Banner Effect Header Plugin for WordPress
CVE-2015-1384
Currently unrated
Summary
The Banner Effect Header plugin for WordPress contains a Cross-Site Scripting (XSS) weakness that enables remote attackers to execute arbitrary scripts or HTML by manipulating the 'banner_effect_divid' parameter in the options page accessed through the wp-admin interface. This allows unauthorized actors to potentially compromise the security of the affected installations.
References
Timeline
Vulnerability published
Vulnerability Reserved