plugin

Efence Vulnerabilities

1 known security issue reported for the Efence WordPress plugin. Most recent disclosed May 28, 2014.

1 medium

Running Efence on your site? Check whether your installed version is affected.

Scan your site free

efence <= 1.3.2 - Multiple Cross-Site Scripting

medium

Multiple cross-site scripting (XSS) vulnerabilities in callback.php in the efence plugin 1.3.2 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) message, (2) zoneid, (3) pubKey, or (4) privKey parameter.

CVSS:
6.1
Affected:
up to 1.3.2
Fix:
No patched version reported
Disclosed:
May 28, 2014

CVE-2014-4526 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database