Cross-Site Scripting Vulnerability in Post Connector Plugin by WordPress
CVE-2015-9362
6.1MEDIUM
What is CVE-2015-9362?
The Post Connector plugin for WordPress is susceptible to a cross-site scripting (XSS) attack due to improper handling of user-supplied data in add_query_arg() and remove_query_arg(). This vulnerability can allow attackers to inject arbitrary JavaScript into web pages viewed by other users, potentially leading to data theft or website compromise. It is essential to upgrade to version 1.0.4 or later to mitigate the risks associated with this issue.