CVE-2010-4779: XSS
Cross-site scripting (XSS) vulnerability in lib/includes/auth.inc.php in the WPtouch plugin 1.9.19.4 and 1.9.20 for WordPress allows remote attackers to inject arbitrary web script or HTML via the wptouchsettings parameter to include/adsense-new.php. NOTE: some of these details are obtained from third party information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-4779?
CVE-2010-4779 is considered a high severity vulnerability due to its potential for exploitation through cross-site scripting.
How do I fix CVE-2010-4779?
To fix CVE-2010-4779, update the WPtouch plugin to version 1.9.21 or later, which addresses the XSS vulnerability.
What impact does CVE-2010-4779 have on my WordPress site?
CVE-2010-4779 may allow remote attackers to inject malicious scripts into web pages viewed by users, potentially compromising their data.
Which software versions are affected by CVE-2010-4779?
CVE-2010-4779 affects WPtouch versions 1.9.19.4 and 1.9.20.
Is my WordPress installation vulnerable to CVE-2010-4779?
Only installations using the affected versions of the WPtouch plugin (1.9.19.4 or 1.9.20) are vulnerable to CVE-2010-4779.