CVE-2014-1232
NONE EPSS 77.9%
Published Jan 8, 201412y ago · Modified Jun 17, 20262w ago
Published Jan 8, 2014 12y ago
Last Modified Jun 17, 2026 2w ago
Description
Cross-site scripting (XSS) vulnerability in the Foliopress WYSIWYG plugin before 2.6.8.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Threat Intelligence
EPSS Exploit Probability
77.9% percentile
Exploit & Patch Status
No Known Exploit
Patch Available
Weaknesses 1
CWE-79 Cross-site Scripting Injection
Affected Products 6
| Vendor | Product | Version | Range |
|---|---|---|---|
| foliovision | foliopress_wysiwyg | * | ≤2.6.8.4 |
| foliovision | foliopress_wysiwyg | 2.6.8 | any |
| foliovision | foliopress_wysiwyg | 2.6.8.1 | any |
| foliovision | foliopress_wysiwyg | 2.6.8.2 | any |
| foliovision | foliopress_wysiwyg | 2.6.8.3 | any |
| wordpress | wordpress | * | any |
References 4
- secunia.com http://secunia.com/advisories/56261
- wordpress.org http://wordpress.org/plugins/foliopress-wysiwyg/changelog
- securityfocus.com http://www.securityfocus.com/bid/64666
- exchange.xforce.ibmcloud.com https://exchange.xforce.ibmcloud.com/vulnerabilities/90102
Remediation
- wordpress.org http://wordpress.org/plugins/foliopress-wysiwyg/changelog