CVE-2016-1160: XSS
Published Mar 26, 2016
·Updated
Cross-site scripting (XSS) vulnerability in the WP Favorite Posts plugin before 1.6.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
1 affected component
Wp Favorite Posts Project Wp Favorite Posts Wordpress<=1.6.2
Remediation
Patch Available
Event History
Mar 26, 2016
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-1160?
CVE-2016-1160 has a medium severity rating of 6.1.
2
How do I fix CVE-2016-1160?
To fix CVE-2016-1160, you should update the WP Favorite Posts plugin to version 1.6.6 or later.
3
What type of vulnerability is CVE-2016-1160?
CVE-2016-1160 is a cross-site scripting (XSS) vulnerability.
4
Who is affected by CVE-2016-1160?
CVE-2016-1160 affects users of the WP Favorite Posts plugin for WordPress versions prior to 1.6.6.
5
What can attackers do with CVE-2016-1160?
Attackers can inject arbitrary web scripts or HTML into the affected sites through CVE-2016-1160.