codevigilant.com
http://codevigilant.com/disclosure/wp-plugin-ultimate-weather-plugin-a3-cross-site-scripting-xss CVE-2014-4561
MEDIUMNuclei
Ultimate Weather Plugin <= 1.0 - Cross-Site Scripting
Record summary
CVE-2014-4561 has a selected CVSS score of 6.1 (medium); EIP currently links 1 curated repository PoC and 1 Nuclei template.
Proofs of concept
1Curated repository PoCs
GitHubCVE-2014-4561Curated repository PoCby yubsyStars: 112Not analyzed1 file
Nuclei templates
1ProjectDiscoveryMEDIUMUltimate Weather Plugin <= 1.0 - Cross-Site ScriptingCVSS 6.1
The ultimate-weather plugin 1.0 for WordPress contains a cross-site scripting vulnerability.
Impact
Successful exploitation of this vulnerability could allow an attacker to inject malicious scripts into the plugin's output, potentially leading to the execution of arbitrary code or stealing sensitive information.
Remediation
Upgrade to a patched version of the Ultimate Weather Plugin that addresses the XSS vulnerability.
WeaknessesCWE-79
Authorsdaffainfo
Template tagscve2014cvewordpresswp-pluginxssweatherwpscanunauthultimate-weather_projectvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:ultimate-weather_project:ultimate-weather:1.0:*:*:*:*:wordpress:*:*
https://wpscan.com/vulnerability/5c358ef6-8059-4767-8bcb-418a45b2352d https://nvd.nist.gov/vuln/detail/CVE-2014-4561 http://codevigilant.com/disclosure/wp-plugin-ultimate-weather-plugin-a3-cross-site-scripting-xss/ https://github.com/ARPSyndicate/kenzer-templates
Source: ProjectDiscovery
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2014-4561