Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in paginas/vista-previa-form.php in the EnvialoSimple: Email Marketing and Newsletters (envialosimple-email-marketing-y-newsletters-gratis) plugin before 1.98 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) FormID or (2) AdministratorID parameter.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Envialosimple | Email Marketing Y Newsletters | <= 1.97 |
Related Weaknesses (CWE)
References
- http://codevigilant.com/disclosure/wp-plugin-envialosimple-email-marketing-y-newExploit
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new
- http://codevigilant.com/disclosure/wp-plugin-envialosimple-email-marketing-y-newExploit
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new
FAQ
What is CVE-2014-4527?
CVE-2014-4527 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Multiple cross-site scripting (XSS) vulnerabilities in paginas/vista-previa-form.php in the EnvialoSimple: Email Marketing and Newsletters (envialosimple-email-marketing-y-newsletters-gratis) plugin b...
How severe is CVE-2014-4527?
CVE-2014-4527 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-4527?
Check the references section above for vendor advisories and patch information. Affected products include: Envialosimple Email Marketing Y Newsletters.