CVE-2014-9570: XSS
Multiple cross-site scripting (XSS) vulnerabilities in the MyWebsiteAdvisor Simple Security plugin 1.1.5 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) datefilter parameter in the accesslog page to wp-admin/users.php or (2) simplesecurityipblacklist[] parameter in an addblacklistip action in the ipblacklist page to wp-admin/users.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9570?
The severity of CVE-2014-9570 is medium, rated at 4.3.
How do I fix CVE-2014-9570?
To fix CVE-2014-9570, update the MyWebsiteAdvisor Simple Security plugin to version 1.1.6 or later.
What types of vulnerabilities does CVE-2014-9570 exploit?
CVE-2014-9570 exploits multiple cross-site scripting (XSS) vulnerabilities.
What impact can CVE-2014-9570 have on my website?
CVE-2014-9570 allows remote attackers to inject arbitrary web scripts or HTML, potentially compromising the security of your website.
Which version of the MyWebsiteAdvisor Simple Security plugin is affected by CVE-2014-9570?
Versions 1.1.5 and earlier of the MyWebsiteAdvisor Simple Security plugin are affected by CVE-2014-9570.