4.3
CVSSv2

CVE-2015-2218

Published: 05/03/2015 Updated: 03/12/2016
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in the wp_ajax_save_item function in wonderpluginaudio.php in the WonderPlugin Audio Player plugin prior to 2.1 for WordPress allow remote malicious users to inject arbitrary web script or HTML via the (1) item[name] or (2) item[customcss] parameter in a wonderplugin_audio_save_item action to wp-admin/admin-ajax.php or the itemid parameter in the (3) wonderplugin_audio_show_item or (4) wonderplugin_audio_edit_item page to wp-admin/admin.php.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

magic hills wonderplugin audio player

Exploits

# Exploit Title: WonderPlugin Audio Player 20 Blind SQL Injection and XSS # Date: 20-01-2015 # Software Link: wwwwonderplugincom/wordpress-audio-player/ # Exploit Author: Kacper Szurek # Contact: twittercom/KacperSzurek # Website: securityszurekpl/ # Category: webapps 1 Description wp_ajax_save_item() is accessible f ...