WP Media Cleaner [wp-media-cleaner] < 2.4.0
unknown
[en] Multiple cross-site scripting (XSS) vulnerabilities in the WP Media Cleaner plugin 2.2.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) view, (2) paged, or (3) s parameter in the wp-media-cleaner page to wp-admin/upload.php.
- Affected:
- up to 2.4.0
- Fixed in:
- 2.4.0
- Disclosed:
- Mar 3, 2015
CVE-2015-2195 on NVD →
WP Media Cleaner <= 2.2.6 - Cross-Site Scripting
medium
Multiple cross-site scripting (XSS) vulnerabilities in the WP Media Cleaner plugin 2.2.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) view, (2) paged, or (3) s parameter in the wp-media-cleaner page to wp-admin/upload.php.
- CVSS:
- 6.1
- Affected:
- up to 2.2.6
- Fixed in:
- 2.4.0
- Disclosed:
- Feb 26, 2015
CVE-2015-2195 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database