Record summary

CVE-2015-1494 has a selected CVSS score of 4.3; EIP currently links 1 catalogued exploit.

Description

The FancyBox for WordPress plugin before 3.0.3 for WordPress does not properly restrict access, which allows remote attackers to conduct cross-site scripting (XSS) attacks via an mfbfw[*] parameter in an update action to wp-admin/admin-post.php, as demonstrated by the mfbfw[padding] parameter and exploited in the wild in February 2015.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Feb 17, 2015 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Catalogued exploits
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Proofs of concept

1

Catalogued exploits

ExploitDBWordPress Plugin Fancybox 3.0.2 - Persistent Cross-Site ScriptingExploitDB exploitby NULLpOint7rNot analyzed1 file
ExploitDB

PoC details

References

9