CVE-2014-4535
MEDIUM EXPLOITED NUCLEIWordPress <0.1 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in the Import Legacy Media plugin 0.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the filename parameter to getid3/demos/demo.mimeonly.php.
Nuclei Templates (1)
Import Legacy Media <= 0.1 - Cross-Site Scripting
MEDIUMby daffainfo
Scores
CVSS v3
6.1
EPSS
0.0380
EPSS Percentile
88.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
VulnCheck KEV
2024-09-19
CWE
CWE-79
Status
published
Products (1)
import_legacy_media_project/import_legacy_media
< 0.1
Published
Dec 27, 2019
Tracked Since
Feb 18, 2026