CVE-2015-3647: XSS
Multiple cross-site scripting (XSS) vulnerabilities in wppa-ajax-front.php in the WP Photo Album Plus (aka WPPA) plugin before 6.1.3 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) comemail or (2) comname parameter in a wppa do-comment action.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-3647?
CVE-2015-3647 is classified as a moderate severity vulnerability due to the potential for cross-site scripting attacks.
How do I fix CVE-2015-3647?
To fix CVE-2015-3647, update the WP Photo Album Plus plugin to version 6.1.3 or later.
What components are affected by CVE-2015-3647?
CVE-2015-3647 affects the WP Photo Album Plus plugin versions prior to 6.1.3 for WordPress.
What are the attack vectors for CVE-2015-3647?
Attackers can exploit CVE-2015-3647 through the comemail or comname parameters in a wppa do-comment action.
Who can be impacted by CVE-2015-3647?
Websites using vulnerable versions of the WP Photo Album Plus plugin are at risk of being targeted by attackers.