CVSS Summary
Score | 6.8 Medium |
---|---|
Vector | Network |
Complexity | Medium |
Authentication | None |
Confidentiality | Partial |
Integrity | Partial |
Availability | Partial |
Last revised:
This plugin is vulnerable to a reflected XSS attack. An attacker able to convince a logged in admin to visit a particular URL will be able to do anything an admin can do.
Current state: Fixed
Score | 6.8 Medium |
---|---|
Vector | Network |
Complexity | Medium |
Authentication | None |
Confidentiality | Partial |
Integrity | Partial |
Availability | Partial |
Log in as an admin on a multisite installation, visit this URL (replacing localhost with the appropriate domain name):
http://localhost/wp-admin/network/users.php?page=unconfirmed&s=%22%3E%3Cscript%3Ealert%281%29%3C/script%3E
Upgrade to version 1.2.5.