Cross-Site Scripting Vulnerability in TheCartPress Boot Store Theme by WordPress
CVE-2015-4582
6.1MEDIUM
What is CVE-2015-4582?
The TheCartPress Boot Store theme version 1.6.4 for WordPress contains a vulnerability that allows attackers to exploit the 'header.php' file via Cross-Site Scripting (XSS). This flaw enables unauthorized scripts to be executed in the context of users interacting with the affected site, potentially leading to data theft or account compromise.
Affected Version(s)
boot-store 1.6.4