CVE-2014-5240: XSS
Cross-site scripting (XSS) vulnerability in wp-includes/pluggable.php in WordPress before 3.9.2, when Multisite is enabled, allows remote authenticated administrators to inject arbitrary web script or HTML, and obtain Super Admin privileges, via a crafted avatar URL.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-5240?
CVE-2014-5240 has a medium severity level as it allows remote authenticated administrators to exploit a cross-site scripting vulnerability.
How do I fix CVE-2014-5240?
To fix CVE-2014-5240, upgrade WordPress to version 3.9.2 or later.
Who is affected by CVE-2014-5240?
CVE-2014-5240 affects WordPress versions before 3.9.2 when Multisite is enabled.
What kind of attack can be executed using CVE-2014-5240?
An attacker can exploit CVE-2014-5240 to inject arbitrary web script or HTML, potentially gaining Super Admin privileges.
Is CVE-2014-5240 specific to certain versions of WordPress?
Yes, CVE-2014-5240 specifically affects multiple versions of WordPress prior to 3.9.2.