CVE-2014-8800: XSS
Cross-site scripting (XSS) vulnerability in nextend-facebook-settings.php in the Nextend Facebook Connect plugin before 1.5.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the fbloginbutton parameter in a newfbupdateoptions action.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-8800?
CVE-2014-8800 has a medium severity rating due to its potential for remote exploitation through XSS.
How do I fix CVE-2014-8800?
To fix CVE-2014-8800, update the Nextend Facebook Connect plugin to version 1.5.1 or later.
What type of vulnerability is CVE-2014-8800?
CVE-2014-8800 is classified as a cross-site scripting (XSS) vulnerability.
What software is affected by CVE-2014-8800?
CVE-2014-8800 affects versions of the Nextend Facebook Connect plugin for WordPress prior to 1.5.1.
What are the potential impacts of CVE-2014-8800?
The impact of CVE-2014-8800 includes the possibility of an attacker injecting malicious web scripts or HTML into a vulnerable WordPress site.