XSS Vulnerability in Broken Link Manager Plugin for WordPress
CVE-2015-9468
6.1MEDIUM
Summary
The Broken Link Manager plugin version 0.4.5 for WordPress is susceptible to a Cross-Site Scripting (XSS) vulnerability. This security flaw occurs through an unsanitized input in the page parameter during the delURL action, allowing attackers to inject malicious scripts. This exploitation can lead to unauthorized actions on behalf of users and compromise the integrity of the affected WordPress site.
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved