First published: Tue Feb 17 2015(Updated: )
The FancyBox for WordPress plugin before 3.0.3 for WordPress does not properly restrict access, which allows remote attackers to conduct cross-site scripting (XSS) attacks via an mfbfw[*] parameter in an update action to wp-admin/admin-post.php, as demonstrated by the mfbfw[padding] parameter and exploited in the wild in February 2015.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
FancyBox | <=3.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-1494 has a moderate severity rating due to its potential to allow cross-site scripting (XSS) attacks.
To fix CVE-2015-1494, update the FancyBox for WordPress plugin to version 3.0.3 or later.
CVE-2015-1494 enables remote attackers to conduct cross-site scripting (XSS) attacks.
Versions of the FancyBox for WordPress plugin prior to 3.0.3 are affected by CVE-2015-1494.
The vulnerability can be exploited via the mfbfw[*] parameter in an update action to wp-admin/admin-post.php.