4.3
CVSSv2

CVE-2015-1494

Published: 17/02/2015 Updated: 13/09/2021
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

The FancyBox for WordPress plugin prior to 3.0.3 for WordPress does not properly restrict access, which allows remote malicious users to conduct cross-site scripting (XSS) attacks via an mfbfw[*] parameter in an update action to wp-admin/admin-post.php, as demonstrated by the mfbfw[padding] parameter and exploited in the wild in February 2015.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

colorlib fancybox

Exploits

# Exploit Title: Wordpress plugin Fancybox-for-WordPress Stored XSS # Exploit Author: NULLpOint7r # Date: 2015-02-11 # Contact me: seidbenseidok@gmailcom # Version: 302 # Download link: downloadswordpressorg/plugin/fancybox-for-wordpress302zip # Home: wwwsec4evercom/home/ vulnerable code [fancyboxphp]: 342 if ( isset ...