CVE-2015-9428: XSS
The wplegalpages plugin before 1.1 for WordPress has CSRF with resultant XSS via wp-admin/admin.php?page=legal-pages lp-domain-name, lp-business-name, lp-phone, lp-street, lp-city-state, lp-country, lp-email, lp-address, or lp-niche parameters.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2015-9428?
CVE-2015-9428 is a vulnerability in the wplegalpages plugin for WordPress that allows for CSRF attacks with resultant XSS via specific parameters.
How severe is CVE-2015-9428?
CVE-2015-9428 has a severity rating of 6.5, which is considered medium.
Which software versions are affected by CVE-2015-9428?
CVE-2015-9428 affects wplegalpages plugin versions up to but not including 1.1 for WordPress.
How can I fix CVE-2015-9428?
To fix CVE-2015-9428, it is recommended to update the wplegalpages plugin to version 1.1 or a higher version.
Can you provide more information about CVE-2015-9428?
More information about CVE-2015-9428 can be found on the WPScan Vulnerability Database and the WordPress plugin page for wplegalpages.