CVE-2016-4566: XSS
Published May 22, 2016
·Updated
Cross-site scripting (XSS) vulnerability in plupload.flash.swf in Plupload before 2.1.9, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via a Same-Origin Method Execution (SOME) attack.
Affected Software
2 affected components
WordPress WordPress<=4.5.1
plupload plupload<=2.1.8
Remediation
Patch Available
Patch Available
Patch Available
Event History
May 22, 2016
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-4566?
CVE-2016-4566 is categorized as a critical cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2016-4566?
To mitigate CVE-2016-4566, upgrade Plupload to version 2.1.9 or later and WordPress to version 4.5.2 or later.
3
What software is affected by CVE-2016-4566?
CVE-2016-4566 affects Plupload versions prior to 2.1.9 and WordPress versions prior to 4.5.2.
4
What type of attack does CVE-2016-4566 enable?
CVE-2016-4566 allows remote attackers to execute Same-Origin Method Execution (SOME) attacks.
5
Can CVE-2016-4566 be exploited remotely?
Yes, CVE-2016-4566 can be exploited remotely to inject arbitrary web scripts or HTML.