Simple Security [simple-security] < 1.1.6
unknown
[en] Multiple cross-site scripting (XSS) vulnerabilities in the MyWebsiteAdvisor Simple Security plugin 1.1.5 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) datefilter parameter in the access_log page to wp-admin/users.php or (2) simple_security_ip_blacklist[] parame...
- Affected:
- up to 1.1.6
- Fixed in:
- 1.1.6
- Disclosed:
- Jan 15, 2015
CVE-2014-9570 on NVD →
Simple Security <= 1.1.5 - Authenticated Stored Cross-Site Scripting
medium
The Simple Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'datefilter' parameter found on the access_log page to wp-admin/users.php and the 'simple_security_ip_blacklist[]' parameter found in the add_blacklist_ip action on the ip_blacklist page to wp-admin/users.php in versions up to...
- CVSS:
- 4.8
- Affected:
- up to 1.1.5
- Fixed in:
- 1.1.6
- Disclosed:
- Jan 14, 2015
CVE-2014-9570 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database