VulnerabilityModified
CVE-2014-4603
Multiple cross-site scripting (XSS) vulnerabilities in yupdates_application.php in the Yahoo!
MEDIUM 4.3EPSS 1.62%
Does this matter?
Lower severity and a low EPSS score (1.62%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site scripting (XSS) vulnerabilities in yupdates_application.php in the Yahoo! Updates for WordPress plugin 1.0 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) secret, (2) key, or (3) appid parameter.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.62% probability · 75th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- yahoo\! updates for wordpress plugin project/yahoo\! updates for wordpress plugin
- Source
- cve@mitre.org
References
- http://codevigilant.com/disclosure/wp-plugin-yahoo-updates-for-wordpress-a3-cross-site-scripting-xssExploit
- http://www.securityfocus.com/bid/68401Exploit
- http://codevigilant.com/disclosure/wp-plugin-yahoo-updates-for-wordpress-a3-cross-site-scripting-xssExploit
- http://www.securityfocus.com/bid/68401Exploit
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.