Cross-Site Scripting Vulnerability in XCloner Plugin for WordPress
CVE-2015-4337

Currently unrated

Key Information:

Vendor
Wordpress
Status
Vendor
CVE Published:
17 June 2015

Summary

The XCloner plugin version 3.1.2 for WordPress is susceptible to a cross-site scripting (XSS) vulnerability. This weakness allows remote authenticated users to inject arbitrary web scripts or HTML into the application. By manipulating the 'excl_manual' parameter in the xcloner_show page accessed through wp-admin/plugins.php, attackers can exploit this vulnerability to execute malicious scripts in the context of other users, potentially compromising user sessions and leading to unauthorized actions.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.