CVE-2014-4536: XSS
Multiple cross-site scripting (XSS) vulnerabilities in tests/notAutotestContactServicepauseCampaign.php in the Infusionsoft Gravity Forms plugin before 1.5.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) go, (2) contactId, or (3) campaignId parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-4536?
CVE-2014-4536 is classified as a high severity vulnerability due to its potential for remote code execution via cross-site scripting.
How do I fix CVE-2014-4536?
To fix CVE-2014-4536, update the Infusionsoft Gravity Forms plugin to version 1.5.6 or later.
What are the affected versions of CVE-2014-4536?
CVE-2014-4536 affects versions of the Infusionsoft Gravity Forms plugin prior to 1.5.6.
What type of vulnerability is CVE-2014-4536?
CVE-2014-4536 is a cross-site scripting (XSS) vulnerability that allows remote code injection.
Which parameters are exploited in CVE-2014-4536?
CVE-2014-4536 can be exploited through the (1) go, (2) contactId, or (3) campaignId parameters.