Record summary

CVE-2014-4550 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

Cross-site scripting (XSS) vulnerability in preview-shortcode-external.php in the Shortcode Ninja plugin 1.4 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the shortcode parameter.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryMEDIUMShortcode Ninja <= 1.4 - Cross-Site ScriptingCVSS 6.1

A cross-site scripting vulnerability in preview-shortcode-external.php in the Shortcode Ninja plugin 1.4 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the shortcode parameter.

Impact

Allows remote attackers to inject arbitrary web script or HTML via crafted shortcode parameters, leading to potential session hijacking, defacement of web pages, or theft of sensitive information.

Remediation

Update to the latest version of the Shortcode Ninja plugin (1.4 or higher) to fix the XSS vulnerability.

WeaknessesCWE-79
Authorsdaffainfo
Template tagscve2014cvewordpresswp-pluginxsswpscanunauthvisualshortcodesvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:visualshortcodes:ninja:*:*:*:*:*:wordpress:*:*
Google: inurl:"/wp-content/plugins/shortcode-ninja"

Source: ProjectDiscovery

References

2