CVE-2014-4592
WP Planet <= 0.1 - Cross-Site Scripting
Record summary
CVE-2014-4592 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
Cross-site scripting (XSS) vulnerability in rss.class/scripts/magpie_debug.php in the WP-Planet plugin 0.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the url parameter.
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryMEDIUMWP Planet <= 0.1 - Cross-Site ScriptingCVSS 6.1
A cross-site scripting vulnerability in rss.class/scripts/magpie_debug.php in the WP-Planet plugin 0.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the url parameter.
Impact
Attackers can execute arbitrary scripts in the victim's browser, leading to session hijacking or defacement.
Remediation
Update to the latest version of WP-Planet plugin that addresses this vulnerability or remove the vulnerable script.
Source: ProjectDiscovery