First published: Tue Nov 25 2014(Updated: )
Cross-site scripting (XSS) vulnerability in the media-playlists feature in WordPress before 3.9.x before 3.9.3 and 4.x before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress | =3.9 | |
WordPress | =3.9.1 | |
WordPress | =3.9.2 | |
WordPress | =4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-9032 has a medium severity level due to its potential for cross-site scripting attacks.
To fix CVE-2014-9032, upgrade to WordPress version 3.9.3 or later, or 4.0.1 or later.
CVE-2014-9032 allows remote attackers to perform cross-site scripting attacks by injecting arbitrary web scripts or HTML.
CVE-2014-9032 affects WordPress versions 3.9, 3.9.1, 3.9.2, and 4.0 prior to 4.0.1.
CVE-2014-9032 is not a concern for users of current versions of WordPress, as the vulnerability has been patched.