3.5
CVSSv2

CVE-2014-9311

Published: 14/04/2015 Updated: 15/04/2015
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
VMScore: 355
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in admin.php in the Shareaholic plugin prior to 7.6.1.0 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the location[id] parameter in a shareaholic_add_location action to wp-admin/admin-ajax.php.

Vulnerable Product Search on Vulmon Subscribe to Product

shareaholic shareaholic

Exploits

# Exploit Title: Shareaholic 7603 XSS # Date: 10-11-2014 # Software Link: wordpressorg/plugins/shareaholic/ # Exploit Author: Kacper Szurek # Contact: twittercom/KacperSzurek # Website: securityszurekpl/ # CVE: CVE-2014-9311 # Category: webapps 1 Description ShareaholicAdmin::add_location is accessible for every regi ...
WordPress Shareaholic plugin version 7603 suffers from a cross site scripting vulnerability ...