CVE-2015-4557: XSS
Cross-site scripting (XSS) vulnerability in the newTwittersignbutton function in nextend-Twitter-connect.php in the Nextend Twitter Connect plugin before 1.5.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the redirectto parameter. NOTE: this may overlap CVE-2015-4413.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-4557?
CVE-2015-4557 has a medium severity rating due to its potential for cross-site scripting attacks.
How do I fix CVE-2015-4557?
To fix CVE-2015-4557, update the Nextend Twitter Connect plugin to version 1.5.2 or later.
Who is affected by CVE-2015-4557?
CVE-2015-4557 affects users of the Nextend Twitter Connect plugin for WordPress versions prior to 1.5.2.
What types of attacks can CVE-2015-4557 enable?
CVE-2015-4557 can enable remote attackers to execute arbitrary web scripts or HTML through cross-site scripting.
Is CVE-2015-4557 still a risk in newer versions of WordPress?
CVE-2015-4557 is no longer a risk in WordPress if the Nextend Twitter Connect plugin has been updated to version 1.5.2 or higher.