CVE-2015-3439
WordPress Core < 4.1.2 - Cross-Site Scripting via Ephox in Plupload
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
Cross-site scripting (XSS) vulnerability in the Ephox (formerly Moxiecode) plupload.flash.swf shim 2.1.2 in Plupload, as used in WordPress 3.9.x, 4.0.x, and 4.1.x before 4.1.2 and other products, allows remote attackers to execute same-origin JavaScript functions via the target parameter, as demonstrated by executing a certain click function, related to _init.as and _fireEvent.as.
Vulnerabilidad de XSS en el shim Ephox (anteriormente Moxiecode) plupload.flash.swf 2.1.2 en Plupload, tal como se utiliza en WordPress 3.9.x, 4.0.x y 4.1.x en versiones anteriores a 4.1.2 y otros productos, permite a atacantes remotos ejecutar funciones JavaScript del mismo origen a través del parámetro target, según lo demostrado ejecutando cierta función de clic, relacionada con _init.as y _fireEvents.as.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2015-04-20 CVE Published
- 2015-04-28 CVE Reserved
- 2024-04-11 EPSS Updated
- 2024-08-06 CVE Updated
- 2024-08-06 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (11)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/74269 | Vdb Entry | |
http://www.securitytracker.com/id/1032207 | Vdb Entry | |
https://core.trac.wordpress.org/changeset/32168 | X_refsource_confirm | |
https://wpvulndb.com/vulnerabilities/7933 | X_refsource_misc |
URL | Date | SRC |
---|---|---|
http://codex.wordpress.org/Version_4.1.2 | 2024-08-06 | |
http://zoczus.blogspot.com/2015/04/plupload-same-origin-method-execution.html | 2024-08-06 | |
https://wordpress.org/news/2015/04/wordpress-4-1-2 | 2024-08-06 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 7.0 Search vendor "Debian" for product "Debian Linux" and version "7.0" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 8.0 Search vendor "Debian" for product "Debian Linux" and version "8.0" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 3.9.0 Search vendor "Wordpress" for product "Wordpress" and version "3.9.0" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 3.9.1 Search vendor "Wordpress" for product "Wordpress" and version "3.9.1" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 3.9.2 Search vendor "Wordpress" for product "Wordpress" and version "3.9.2" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 3.9.3 Search vendor "Wordpress" for product "Wordpress" and version "3.9.3" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 4.0 Search vendor "Wordpress" for product "Wordpress" and version "4.0" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 4.0.1 Search vendor "Wordpress" for product "Wordpress" and version "4.0.1" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 4.1 Search vendor "Wordpress" for product "Wordpress" and version "4.1" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 4.1.1 Search vendor "Wordpress" for product "Wordpress" and version "4.1.1" | - |
Affected
|