MEDIUM
Cross-site scripting (XSS) vulnerability in the Google Doc Embedder plugin before 2.5.19 for WordPress allows remote attackers to inject arbitrary web script or HTML via the profile parameter in an edit action in the gde-settings page to wp-admin/options-general.php
Published Feb 19, 2015
4.3
MEDIUMCVSS 2.0
EPSS 2.07%
Description
Affected products
Remediation
Metrics
References (3)
Change history (0)
No recorded changes yet.