Record summary

CVE-2014-9444 has a selected CVSS score of 4.3; EIP currently links 1 Nuclei template.

Description

Cross-site scripting (XSS) vulnerability in the Frontend Uploader plugin 0.9.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the errors[fu-disallowed-mime-type][0][name] parameter to the default URI.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryMEDIUMFrontend Uploader <= 0.9.2 - Cross-Site ScriptingCVSS 4.3

The Frontend Uploader WordPress plugin prior to v.0.9.2 was affected by an unauthenticated Cross-Site Scripting security vulnerability.

Impact

Allows remote attackers to inject arbitrary web script or HTML via a crafted file name, leading to potential session hijacking, defacement, or data theft.

Remediation

Update to the latest version of the Frontend Uploader plugin (0.9.2) or apply the vendor-supplied patch to fix the vulnerability.

WeaknessesCWE-79
Authorsdaffainfo
Template tagscve2014cvewp-pluginxsswpscanpacketstormwordpressunauthfrontend_uploader_projectvuln
CVSS vector: CVSS:2.0/AV:N/AC:M/Au:N/C:N/I:P/A:N
CPE: cpe:2.3:a:frontend_uploader_project:frontend_uploader:0.9.2:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

4