CVE-2014-4576: XSS
Published Jul 2, 2014
·Updated
Cross-site scripting (XSS) vulnerability in services/diagnostics.php in the WordPress Social Login plugin 2.0.3 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the xhrurl parameter.
Affected Software
1 affected component
Wordpress Social Login Project Wordpress Social Login Wordpress<=2.0.3
Event History
Jul 2, 2014
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-4576?
CVE-2014-4576 has a medium severity rating due to its potential to allow remote attackers to execute arbitrary scripts.
2
How do I fix CVE-2014-4576?
To fix CVE-2014-4576, update the WordPress Social Login plugin to version 2.0.4 or later.
3
What kind of attack can be launched due to CVE-2014-4576?
CVE-2014-4576 allows attackers to perform cross-site scripting (XSS) attacks, which can compromise user sessions.
4
Which versions of the WordPress Social Login plugin are affected by CVE-2014-4576?
CVE-2014-4576 affects WordPress Social Login plugin versions 2.0.3 and earlier.
5
Where is the vulnerability CVE-2014-4576 located within the WordPress Social Login plugin?
The vulnerability CVE-2014-4576 is located in the services/diagnostics.php file within the plugin.