4.3
CVSSv2

CVE-2015-2807

Published: 01/09/2015 Updated: 22/12/2016
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in js/window.php in the Navis DocumentCloud plugin prior to 0.1.1 for WordPress allows remote malicious users to inject arbitrary web script or HTML via the wpbase parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

documentcloud navis documentcloud

Exploits

WordPress Navis DocumentCloud plugin version 01 suffers from a cross site scripting vulnerability ...

Github Repositories

WordPress.org Plugin Mirror

DocumentCloud WordPress plugin The DocumentCloud WordPress plugin lets you embed DocumentCloud resources into WordPress content using shortcodes [documentcloud url="wwwdocumentcloudorg/documents/282753-lefler-thesishtml"] Installation Upload the contents of the plugin to wp-content/plugins/documentcloud Activate the