PT-2019-7459 · WordPress+1 · The Exquisite Ultimate Newspaper Theme+1
Published
2019-10-22
·
Updated
2019-10-24
·
CVE-2015-9500
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
The Exquisite Ultimate Newspaper theme version 1.3.3 for WordPress
Description
The issue is related to a Cross-Site Scripting (XSS) vulnerability. It occurs via the anchor identifier to the
assets/js/jquery.foundation.plugins.js file. This allows for potential malicious script execution.Recommendations
For The Exquisite Ultimate Newspaper theme version 1.3.3, consider disabling access to the
assets/js/jquery.foundation.plugins.js file until a patch is available. Restrict the use of the anchor identifier to minimize the risk of exploitation.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
The Exquisite Ultimate Newspaper Theme
Jquery