CVE-2014-4535

MEDIUM EXPLOITED NUCLEI

WordPress <0.1 - XSS

Title source: llm

Description

Cross-site scripting (XSS) vulnerability in the Import Legacy Media plugin 0.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the filename parameter to getid3/demos/demo.mimeonly.php.

Nuclei Templates (1)

Import Legacy Media <= 0.1 - Cross-Site Scripting
MEDIUMby daffainfo

Scores

CVSS v3 6.1
EPSS 0.0380
EPSS Percentile 88.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

VulnCheck KEV 2024-09-19
CWE
CWE-79
Status published
Products (1)
import_legacy_media_project/import_legacy_media < 0.1
Published Dec 27, 2019
Tracked Since Feb 18, 2026