CVE-2014-7956 – Pods <= 2.4.3 - Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2014-7956
Cross-site scripting (XSS) vulnerability in the Pods plugin before 2.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the id parameter in an edit action in the pods page to wp-admin/admin.php. Vulnerabilidad de XSS en el plugin Pods anterior a.5 para WordPress permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a través del parámetro id en una acción de editar en la página pods en wp-admin/admin.php. WordPress Pods plugin versions 2.4.3 and below suffer from cross site request forgery and cross site scripting vulnerabilities. • http://packetstormsecurity.com/files/129890/WordPress-Pods-2.4.3-CSRF-Cross-Site-Scripting.html http://seclists.org/fulldisclosure/2015/Jan/26 http://www.securityfocus.com/archive/1/534437/100/0/threaded http://www.securityfocus.com/bid/71995 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •