First published: Sun Sep 23 2012(Updated: )
Cross-site scripting (XSS) vulnerability in vendors/samswhois/samswhois.inc.php in the Whois Search plugin before 1.4.2.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the domain parameter, a different vulnerability than CVE-2011-5193.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress | ||
Phpace Samswhois | <=1.4.2.3 | |
Phpace Samswhois | =1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-5194 is classified as a high severity cross-site scripting (XSS) vulnerability.
To fix CVE-2011-5194, update the Whois Search plugin to version 1.4.2.4 or later.
Exploitation of CVE-2011-5194 can allow remote attackers to inject malicious scripts into web pages viewed by users.
All versions of the Whois Search plugin prior to 1.4.2.4 are affected by CVE-2011-5194.
No, WordPress itself is not vulnerable but the Whois Search plugin within it has the vulnerability.