CVE-2014-2040: XSS
Multiple cross-site scripting (XSS) vulnerabilities in the (1) callbackmulticheck, (2) callbackradio, and (3) callbackwysiwygin functions in mfrhclass.settings-api.php in the Media File Renamer plugin 1.7.0 for WordPress allow remote authenticated users with permissions to add media or edit media to inject arbitrary web script or HTML via unspecified parameters, as demonstrated by the title of an uploaded file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2040?
CVE-2014-2040 is classified as a moderate severity vulnerability due to its potential for cross-site scripting (XSS) attacks.
How do I fix CVE-2014-2040?
To fix CVE-2014-2040, update the Media File Renamer plugin to the latest version that addresses the XSS vulnerabilities.
Who is affected by CVE-2014-2040?
CVE-2014-2040 affects remote authenticated users with permissions to add media or edit media in WordPress using Media File Renamer version 1.7.0.
What types of vulnerabilities are present in CVE-2014-2040?
CVE-2014-2040 contains multiple cross-site scripting (XSS) vulnerabilities in specific callback functions.
What versions of Media File Renamer are impacted by CVE-2014-2040?
CVE-2014-2040 specifically impacts Media File Renamer version 1.7.0.