CVE-2014-3903

Cakifo theme <1.6.2 - XSS

Title source: llm

Description

Cross-site scripting (XSS) vulnerability in the Cakifo theme 1.x before 1.6.2 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via crafted Exif data.

Scores

EPSS 0.0018
EPSS Percentile 39.4%

Details

CWE
CWE-79
Status published
Products (10)
jayj/cakifo < 1.6.1
jayj/cakifo
jayj/cakifo
jayj/cakifo
jayj/cakifo
jayj/cakifo
jayj/cakifo
jayj/cakifo
jayj/cakifo
n/a/n/a
Published Aug 19, 2014
Tracked Since Feb 18, 2026