SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2015-8350

Multiple cross-site scripting (XSS) vulnerabilities in the Calls to Action plugin before 2.5.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) open-tab parameter in a wp_cta_global_settings action to…

MEDIUM 6.1EPSS 2.65%

Does this matter?

Lower severity and a low EPSS score (2.65%). Track it; it rarely justifies an emergency change on its own.

Description

Multiple cross-site scripting (XSS) vulnerabilities in the Calls to Action plugin before 2.5.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) open-tab parameter in a wp_cta_global_settings action to wp-admin/edit.php or (2) wp-cta-variation-id parameter to ab-testing-call-to-action-example/.

CVSS 3.0
6.1 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
2.65% probability · 85th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
inboundnow/call to action
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.