CVE-2015-1385: XSS
Cross-site scripting (XSS) vulnerability in the Blubrry PowerPress Podcasting plugin before 6.0.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the cat parameter in a powerpress-editcategoryfeed action in the powerpressadmincategoryfeeds.php page to wp-admin/admin.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1385?
CVE-2015-1385 is classified as a medium severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2015-1385?
To fix CVE-2015-1385, update the Blubrry PowerPress Podcasting plugin to version 6.0.1 or later.
What causes CVE-2015-1385?
CVE-2015-1385 is caused by the plugin's failure to properly sanitize user input in the cat parameter.
Who is affected by CVE-2015-1385?
Websites using Blubrry PowerPress Podcasting plugin versions prior to 6.0.1 are affected by CVE-2015-1385.
Can CVE-2015-1385 be exploited?
Yes, CVE-2015-1385 can be exploited by remote attackers to inject arbitrary web scripts or HTML.