CVE-2014-2315: XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Thank You Counter Button plugin 1.8.7 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) thankscaption, (2) thankscaptionstyle, or (3) thanksstyle parameter to wp-admin/options.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2315?
The severity of CVE-2014-2315 is classified as medium risk due to its potential for cross-site scripting attacks.
How do I fix CVE-2014-2315?
To fix CVE-2014-2315, update the Thank You Counter Button plugin to the latest version to resolve the XSS vulnerabilities.
What are the affected parameters in CVE-2014-2315?
The affected parameters in CVE-2014-2315 are thanks_caption, thanks_caption_style, and thanks_style.
Who can exploit CVE-2014-2315?
Remote attackers can exploit CVE-2014-2315 to inject arbitrary web script or HTML into the affected WordPress site.
Is there a known exploit for CVE-2014-2315?
Yes, there are known exploits for CVE-2014-2315, allowing attackers to leverage the XSS vulnerabilities.