CVE-2015-2218
Multiple cross-site scripting (XSS) vulnerabilities in the wp_ajax_save_item function in wonderpluginaudio.php in the WonderPlugin Audio Player plugin before 2.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1)…
Does this matter?
Lower severity and a low EPSS score (4.19%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site scripting (XSS) vulnerabilities in the wp_ajax_save_item function in wonderpluginaudio.php in the WonderPlugin Audio Player plugin before 2.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) item[name] or (2) item[customcss] parameter in a wonderplugin_audio_save_item action to wp-admin/admin-ajax.php or the itemid parameter in the (3) wonderplugin_audio_show_item or (4) wonderplugin_audio_edit_item page to wp-admin/admin.php.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 4.19% probability · 90th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- magic hills/wonderplugin audio player
- Source
- cve@mitre.org
References
- http://osvdb.org/show/osvdb/118510
- http://osvdb.org/show/osvdb/118511
- http://security.szurek.pl/wonderplugin-audio-player-20-blind-sql-injection-and-xss.htmlExploit
- http://www.exploit-db.com/exploits/36086Exploit
- http://www.securityfocus.com/bid/74851
- http://www.wonderplugin.com/wordpress-audio-player/Vendor Advisory
- http://osvdb.org/show/osvdb/118510
- http://osvdb.org/show/osvdb/118511
- http://security.szurek.pl/wonderplugin-audio-player-20-blind-sql-injection-and-xss.htmlExploit
- http://www.exploit-db.com/exploits/36086Exploit
- http://www.securityfocus.com/bid/74851
- http://www.wonderplugin.com/wordpress-audio-player/Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.