eHive Account Details [ehive-account-details] < 2.1.3
unknownBecause of this vulnerability, the attackers can inject arbitrary web script or HTML. Update the plugin.
- Affected:
- up to 2.1.3
- Fixed in:
- 2.1.3
- Disclosed:
- May 14, 2015
plugin
4 known security issues reported for the Ehive Account Details WordPress plugin. Most recent disclosed May 14, 2015.
Running Ehive Account Details on your site? Check whether your installed version is affected.
Scan your site freeBecause of this vulnerability, the attackers can inject arbitrary web script or HTML. Update the plugin.
Cross-site scripting (XSS) vulnerability in the setTimeout function in js/jquery.prettyPhoto.js in prettyPhoto 3.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted PATH_INTO to the default URI.
[en] Cross-site scripting (XSS) vulnerability in the setTimeout function in js/jquery.prettyPhoto.js in prettyPhoto 3.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted PATH_INTO to the default URI.
The jQuery prettyPhoto library bundled with many plugins was found to be vulnerable to DOM Cross-Site Scripting (XSS).
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free