SimpleDark [simpledark] < 1.2.11
unknown
This WordPress theme is prone to a cross-site scripting (XSS) vulnerability via "s" parameter. It allows remote attackers to inject arbitrary script or HTML.
Update the theme.
- Affected:
- up to 1.2.11
- Fixed in:
- 1.2.11
- Disclosed:
- Aug 1, 2014
SimpleDark <= 1.2.11 - Cross-Site Scripting
high
The SimpleDark Theme for WordPress is vulnerable to Cross-Site Scripting via the 's' parameter in versions up to, and including, 1.2.11 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- CVSS:
- 7.1
- Affected:
- up to 1.2.11
- Fix:
- No patched version reported
- Disclosed:
- Mar 1, 2011
SimpleDark [simpledark] <= 1.2.11 (unfixed)
unknown
The SimpleDark Theme for WordPress is vulnerable to Cross-Site Scripting via the 's' parameter in versions up to, and including, 1.2.11 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- Affected:
- up to 1.2.11
- Fix:
- No patched version reported
- Disclosed:
- Mar 1, 2011
SimpleDark [simpledark] <= 1.2.10 (unfixed)
unknown
The SimpleDark WordPress theme was affected by a 's' Parameter Cross Site Scripting security vulnerability.
- Affected:
- up to 1.2.10
- Fix:
- No patched version reported
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database