CVE-2014-4846: XSS
Published Jul 10, 2014
·Updated
Cross-site scripting (XSS) vulnerability in the Meta Slider (ml-slider) plugin 2.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the id parameter to wp-admin/admin.php.
Affected Software
1 affected component
Matchalabs Metaslider Wordpress=2.5
Event History
Jul 10, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-4846?
CVE-2014-4846 is classified as a medium severity vulnerability due to its potential for XSS attacks.
2
How do I fix CVE-2014-4846?
To fix CVE-2014-4846, update the Meta Slider plugin to the latest version or a version that does not have this vulnerability.
3
Who is affected by CVE-2014-4846?
CVE-2014-4846 affects users of the Meta Slider plugin version 2.5 for WordPress.
4
What type of attack does CVE-2014-4846 enable?
CVE-2014-4846 enables remote attackers to execute arbitrary web scripts or HTML due to cross-site scripting.
5
What are the implications of exploiting CVE-2014-4846?
Exploiting CVE-2014-4846 can lead to unauthorized actions on behalf of users, potential data theft, or website defacement.