CVE-2015-4413: XSS
Cross-site scripting (XSS) vulnerability in the newfbsignbutton function in nextend-facebook-connect.php in Nextend Facebook Connect plugin before 1.5.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the redirectto parameter.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-4413?
CVE-2015-4413 is classified as a medium severity cross-site scripting vulnerability.
How do I fix CVE-2015-4413?
To fix CVE-2015-4413, update the Nextend Facebook Connect plugin to version 1.5.6 or later.
What impact does CVE-2015-4413 have on my website?
CVE-2015-4413 allows an attacker to inject arbitrary web scripts or HTML, potentially compromising user data.
Who is affected by CVE-2015-4413?
CVE-2015-4413 affects users of the Nextend Facebook Connect plugin for WordPress versions prior to 1.5.6.
What is the nature of the vulnerability in CVE-2015-4413?
The vulnerability in CVE-2015-4413 is a cross-site scripting (XSS) vulnerability that can be exploited via the redirect_to parameter.