Record summary

CVE-2014-4592 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

Cross-site scripting (XSS) vulnerability in rss.class/scripts/magpie_debug.php in the WP-Planet plugin 0.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the url parameter.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryMEDIUMWP Planet <= 0.1 - Cross-Site ScriptingCVSS 6.1

A cross-site scripting vulnerability in rss.class/scripts/magpie_debug.php in the WP-Planet plugin 0.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the url parameter.

Impact

Attackers can execute arbitrary scripts in the victim's browser, leading to session hijacking or defacement.

Remediation

Update to the latest version of WP-Planet plugin that addresses this vulnerability or remove the vulnerable script.

WeaknessesCWE-79
Authorsdaffainfo
Template tagscve2014cvewordpresswp-pluginxsswpscanunauthczepolvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:czepol:wp-planet:*:*:*:*:*:wordpress:*:*
Google: inurl:"/wp-content/plugins/wp-planet"

Source: ProjectDiscovery

References

2