PT-2014-5996 · WordPress · Wp Consultant
Anant Shrivastava
+1
·
Published
2014-07-02
·
Updated
2014-07-09
·
CVE-2014-4582
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
WP Consultant plugin version 1.0 and earlier
Description
A cross-site scripting issue exists, allowing remote attackers to inject arbitrary web script or HTML. This is achieved via the
dialog id parameter in the admin/admin show dialogs.php file.Recommendations
For WP Consultant plugin version 1.0 and earlier, avoid using the
dialog id parameter in the affected admin/admin show dialogs.php file until a fix is available. Consider temporarily restricting access to this file to minimize the risk of exploitation.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wp Consultant