CVE-2015-2195: XSS
Multiple cross-site scripting (XSS) vulnerabilities in the WP Media Cleaner plugin 2.2.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) view, (2) paged, or (3) s parameter in the wp-media-cleaner page to wp-admin/upload.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2195?
CVE-2015-2195 is rated as a medium severity vulnerability due to its potential for cross-site scripting exploits.
How do I fix CVE-2015-2195?
To fix CVE-2015-2195, you should update the WP Media Cleaner plugin to the latest version that addresses these vulnerabilities.
What are the attack vectors for CVE-2015-2195?
CVE-2015-2195 allows attackers to exploit multiple parameters, specifically view, paged, or s, to inject malicious scripts.
Who is affected by CVE-2015-2195?
CVE-2015-2195 affects users of the WP Media Cleaner plugin version 2.2.6 for WordPress.
What types of vulnerabilities are included in CVE-2015-2195?
CVE-2015-2195 includes multiple cross-site scripting (XSS) vulnerabilities.