Vulnerability Description
Cross-site scripting (XSS) vulnerability in plupload.flash.swf in Plupload before 2.1.9, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via a Same-Origin Method Execution (SOME) attack.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Wordpress | Wordpress | <= 4.5.1 |
| Plupload | Plupload | <= 2.1.8 |
Related Weaknesses (CWE)
References
- http://www.openwall.com/lists/oss-security/2016/05/07/2
- http://www.plupload.com/punbb/viewtopic.php?pid=28690Vendor Advisory
- http://www.securitytracker.com/id/1035818Third Party AdvisoryVDB Entry
- https://codex.wordpress.org/Version_4.5.2Patch
- https://core.trac.wordpress.org/changeset/37382/Patch
- https://gist.github.com/cure53/09a81530a44f6b8173f545accc9ed07eThird Party Advisory
- https://wordpress.org/news/2016/05/wordpress-4-5-2/PatchVendor Advisory
- https://wpvulndb.com/vulnerabilities/8489Third Party Advisory
- http://www.openwall.com/lists/oss-security/2016/05/07/2
- http://www.plupload.com/punbb/viewtopic.php?pid=28690Vendor Advisory
- http://www.securitytracker.com/id/1035818Third Party AdvisoryVDB Entry
- https://codex.wordpress.org/Version_4.5.2Patch
- https://core.trac.wordpress.org/changeset/37382/Patch
- https://gist.github.com/cure53/09a81530a44f6b8173f545accc9ed07eThird Party Advisory
- https://wordpress.org/news/2016/05/wordpress-4-5-2/PatchVendor Advisory
FAQ
What is CVE-2016-4566?
CVE-2016-4566 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Cross-site scripting (XSS) vulnerability in plupload.flash.swf in Plupload before 2.1.9, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via a Same-Or...
How severe is CVE-2016-4566?
CVE-2016-4566 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-4566?
Check the references section above for vendor advisories and patch information. Affected products include: Wordpress Wordpress, Plupload Plupload.