Record summary

CVE-2014-4561 has a selected CVSS score of 6.1 (medium); EIP currently links 1 curated repository PoC and 1 Nuclei template.

Description

The ultimate-weather plugin 1.0 for WordPress has XSS

Description source: CVE List

Exploitation context

Available material

Curated repository PoCs
1
Nuclei templates
1

Proofs of concept

1

Curated repository PoCs

GitHubCVE-2014-4561Curated repository PoCby yubsyStars: 112Not analyzed1 file

Python · 342 B

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMUltimate Weather Plugin <= 1.0 - Cross-Site ScriptingCVSS 6.1

The ultimate-weather plugin 1.0 for WordPress contains a cross-site scripting vulnerability.

Impact

Successful exploitation of this vulnerability could allow an attacker to inject malicious scripts into the plugin's output, potentially leading to the execution of arbitrary code or stealing sensitive information.

Remediation

Upgrade to a patched version of the Ultimate Weather Plugin that addresses the XSS vulnerability.

WeaknessesCWE-79
Authorsdaffainfo
Template tagscve2014cvewordpresswp-pluginxssweatherwpscanunauthultimate-weather_projectvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:ultimate-weather_project:ultimate-weather:1.0:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

2