First published: Wed Jul 02 2014(Updated: )
Cross-site scripting (XSS) vulnerability in wp-plugins-net/index.php in the WP Plugin Manager (wppm) plugin 1.6.4.b and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the filter parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WP Plugin Manager | <=1.6.4.b |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-4593 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2014-4593, you should update the WP Plugin Manager plugin to version 1.6.5 or later.
CVE-2014-4593 can facilitate cross-site scripting (XSS) attacks, allowing attackers to inject arbitrary scripts into web pages.
Users of the WP Plugin Manager plugin version 1.6.4.b and earlier on WordPress are affected by CVE-2014-4593.
The filter parameter in CVE-2014-4593 is a part of the WP Plugin Manager that can be exploited by attackers to inject malicious scripts.