CVE · Medium

CVE-2015-9342 — WP Rollback – Rollback Plugins and Themes [wp-rollback] < 1.2.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2015-9342 WP Rollback – Rollback Plugins and Themes [wp-rollback] < 1.2.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 1.2.3 1.2.3 2015-06-28

CVE-2015-9342

The WP Rollback plugin for WordPress contained both cross-site scripting and cross-site request forgery flaws that could be exploited by attackers. These vulnerabilities were present in versions before 1.2.3, where users could be targeted through malicious scripts or unauthorized actions performed on their behalf. The plugin developers addressed these security issues in version 1.2.3 and later releases.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.