CVE-2014-4550
Shortcode Ninja <= 1.4 - Cross-Site Scripting
Record summary
CVE-2014-4550 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
Cross-site scripting (XSS) vulnerability in preview-shortcode-external.php in the Shortcode Ninja plugin 1.4 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the shortcode parameter.
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryMEDIUMShortcode Ninja <= 1.4 - Cross-Site ScriptingCVSS 6.1
A cross-site scripting vulnerability in preview-shortcode-external.php in the Shortcode Ninja plugin 1.4 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the shortcode parameter.
Impact
Allows remote attackers to inject arbitrary web script or HTML via crafted shortcode parameters, leading to potential session hijacking, defacement of web pages, or theft of sensitive information.
Remediation
Update to the latest version of the Shortcode Ninja plugin (1.4 or higher) to fix the XSS vulnerability.
Source: ProjectDiscovery