Cross-Site Scripting Vulnerability in XCloner Plugin for WordPress
CVE-2015-4337
Currently unrated
Summary
The XCloner plugin version 3.1.2 for WordPress is susceptible to a cross-site scripting (XSS) vulnerability. This weakness allows remote authenticated users to inject arbitrary web scripts or HTML into the application. By manipulating the 'excl_manual' parameter in the xcloner_show page accessed through wp-admin/plugins.php, attackers can exploit this vulnerability to execute malicious scripts in the context of other users, potentially compromising user sessions and leading to unauthorized actions.
References
Timeline
Vulnerability published
Vulnerability Reserved