Cross-site scripting (XSS) vulnerability in the Ephox (formerly Moxiecode) plupload.flash.swf shim 2.1.2 in Plupload, as used in WordPress 3.9.x, 4.0.x, and 4.1.x before 4.1.2 and other products, allows remote attackers to execute same-origin JavaScript functions via the target parameter, as demonstrated by executing a certain click function, related to _init.as and _fireEvent.as.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: debian

Published: 2015-08-05T10:00:00

Updated: 2024-08-06T05:47:57.771Z

Reserved: 2015-04-28T00:00:00

Link: CVE-2015-3439

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2015-08-05T10:59:00.263

Modified: 2016-12-06T03:01:00.537

Link: CVE-2015-3439

cve-icon Redhat

No data.