CVE-2015-5528: XSS
Published Jul 16, 2015
·Updated
Cross-site scripting (XSS) vulnerability in the saveorder function in class-floating-social-bar.php in the Floating Social Bar plugin before 1.1.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the items[] parameter in an fsbsaveorder action to wp-admin/admin-ajax.php.
Affected Software
1 affected component
Wpbeginner Floating Social Bar<=1.1.5
Event History
Jul 16, 2015
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-5528?
CVE-2015-5528 is categorized as a medium severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2015-5528?
To fix CVE-2015-5528, you should update the Floating Social Bar plugin to version 1.1.6 or later.
3
What plugin is affected by CVE-2015-5528?
CVE-2015-5528 affects the Floating Social Bar plugin for WordPress.
4
Can CVE-2015-5528 allow an attacker to execute scripts?
Yes, CVE-2015-5528 allows remote attackers to inject arbitrary web scripts or HTML.
5
What WordPress version is vulnerable to CVE-2015-5528?
Versions of the Floating Social Bar plugin prior to 1.1.6 for WordPress are vulnerable to CVE-2015-5528.