First published: Tue Feb 12 2013(Updated: )
Cross-site scripting (XSS) vulnerability in cached_image.php in the Featurific For WordPress plugin 1.6.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the snum parameter. NOTE: this has been disputed by a third party.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress | =1.6.2 | |
WordPress |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-5265 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2011-5265, it is recommended to update the Featurific For WordPress plugin to a version higher than 1.6.2.
CVE-2011-5265 affects Featurific For WordPress plugin version 1.6.2 when used with WordPress.
CVE-2011-5265 can facilitate cross-site scripting attacks, allowing attackers to inject arbitrary web scripts or HTML.
There have been no reported active exploits specifically targeting CVE-2011-5265, but the vulnerability remains a risk if not patched.