CVE-2015-1494: XSS
The FancyBox for WordPress plugin before 3.0.3 for WordPress does not properly restrict access, which allows remote attackers to conduct cross-site scripting (XSS) attacks via an mfbfw[] parameter in an update action to wp-admin/admin-post.php, as demonstrated by the mfbfw[padding] parameter and exploited in the wild in February 2015.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1494?
CVE-2015-1494 has a moderate severity rating due to its potential to allow cross-site scripting (XSS) attacks.
How do I fix CVE-2015-1494?
To fix CVE-2015-1494, update the FancyBox for WordPress plugin to version 3.0.3 or later.
What types of attacks does CVE-2015-1494 enable?
CVE-2015-1494 enables remote attackers to conduct cross-site scripting (XSS) attacks.
Which versions of the FancyBox for WordPress plugin are affected by CVE-2015-1494?
Versions of the FancyBox for WordPress plugin prior to 3.0.3 are affected by CVE-2015-1494.
What action could be exploited in CVE-2015-1494?
The vulnerability can be exploited via the mfbfw[*] parameter in an update action to wp-admin/admin-post.php.