ThreatPress

WordPress Vulnerabilities Database

Back

WordPress Subscribe To Comments Reloaded Plugin <= 140204 - Stored XSS

Product
Subscribe To Comments Reloaded
Description
This plugin is prone to a options/index.php manager_page parameter stored XSS vulnerability. It allows to perform unauthorized actions in the context of a logged-in user of the affected application.
Solution
Update the plugin.
Classification
Type XSS (Cross Site Scripting)
OWASP Top 10 A3: Cross Site Scripting (XSS)
References
Security Focus
Secunia
CVE
Name CVE-N/A
Versions
Affected In <= 140204
Fixed In 140219
Disclosure date
2014-08-01