CVE-2016-10992: XSS
Published Sep 17, 2019
·Updated
The music-store plugin before 1.0.43 for WordPress has XSS via the wp-admin/admin.php?page=music-store-menu-reports fromyear parameter.
Affected Software
1 affected component
CodePeople Music Store Wordpress<=1.0.141
Event History
Sep 17, 2019
CVE Published
via MITRE·02:36 PM
Data Sourced
via MITRE·02:36 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-10992?
CVE-2016-10992 has a medium severity rating due to its Cross-Site Scripting (XSS) risk.
2
How do I fix CVE-2016-10992?
To fix CVE-2016-10992, update the music-store plugin to version 1.0.43 or later.
3
What systems are affected by CVE-2016-10992?
CVE-2016-10992 affects versions of the music-store plugin for WordPress prior to 1.0.43.
4
What type of vulnerability is CVE-2016-10992?
CVE-2016-10992 is classified as a Cross-Site Scripting (XSS) vulnerability.
5
What can an attacker do with CVE-2016-10992?
An attacker exploiting CVE-2016-10992 could potentially execute arbitrary JavaScript code in the context of a victim's browser.