Improved User Search in Backend <= 1.2.5 - Cross-Site Request Forgery to Cross-Site Scripting
medium
Cross-site request forgery (CSRF) vulnerability in improved-user-search-in-backend.php in the backend in the Improved user search in backend plugin before 1.2.5 for WordPress allows remote attackers to hijack the authentication of administrators for requests that insert XSS sequences via the iusib_meta_fields parameter...
- CVSS:
- 6.1
- Affected:
- up to 1.2.5
- Fixed in:
- 1.2.6
- Disclosed:
- Aug 13, 2014
CVE-2014-5196 on NVD →
Improved user search in backend [improved-user-search-in-backend] < 1.2.6
unknown
[en] Cross-site request forgery (CSRF) vulnerability in improved-user-search-in-backend.php in the backend in the Improved user search in backend plugin before 1.2.5 for WordPress allows remote attackers to hijack the authentication of administrators for requests that insert XSS sequences via the iusib_meta_fields para...
- Affected:
- up to 1.2.6
- Fixed in:
- 1.2.6
- Disclosed:
- Aug 12, 2014
CVE-2014-5196 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database