CVE-2014-4535
40Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 4.0%
from disclosure to weapon
Published on NVDDec 27
VulnCheck+1728d
exploitation probability
4.0%top 10% of all CVEs
observed exploitation
yesVulnCheck
Cross-site scripting (XSS) vulnerability in the Import Legacy Media plugin 0.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the filename parameter to getid3/demos/demo.mimeonly.php.
Affected products
n/a · n/a