Cross-Site Scripting Vulnerability in GD bbPress Attachments Plugin for WordPress
CVE-2015-5481

Currently unrated

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
18 August 2015

Summary

The GD bbPress Attachments plugin for WordPress has a Cross-Site Scripting (XSS) vulnerability located in forms/panels.php. This flaw allows remote attackers to exploit the tab parameter via the gdbbpress_attachments page, leading to the ability to inject arbitrary web scripts or HTML. Affected versions include those prior to 2.3, posing significant risks for WordPress sites utilizing this plugin. Ensure you update to the latest version to mitigate this security issue.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.