CVE-2015-10127: PlusCaptcha Plugin cross site scripting
A vulnerability was found in PlusCaptcha Plugin up to 2.0.6 on WordPress and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting. The attack may be launched remotely. Upgrading to version 2.0.14 is able to address this issue. The patch is identified as 1274afc635170daafd38306487b6bb8a01f78ecd. It is recommended to upgrade the affected component. VDB-248954 is the identifier assigned to this vulnerability.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-10127?
CVE-2015-10127 is classified as problematic due to its potential for cross-site scripting attacks.
How do I fix CVE-2015-10127?
To remediate CVE-2015-10127, upgrade the PlusCaptcha Plugin to version 2.0.14 or later.
What type of vulnerability is CVE-2015-10127?
CVE-2015-10127 is a cross-site scripting (XSS) vulnerability.
Can CVE-2015-10127 be exploited remotely?
Yes, CVE-2015-10127 can be exploited remotely by attackers through vulnerable WordPress installations.
Which versions of PlusCaptcha Plugin are affected by CVE-2015-10127?
CVE-2015-10127 affects PlusCaptcha Plugin versions up to 2.0.6.