CVE Database /
CVE-2015-9342
CVE · Medium
CVE-2015-9342 — WP Rollback – Rollback Plugins and Themes [wp-rollback] < 1.2.3
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2015-9342
|
WP Rollback – Rollback Plugins and Themes [wp-rollback] < 1.2.3 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
6.1
|
< 1.2.3
|
1.2.3 |
2015-06-28 |
—
|
CVE-2015-9342
The WP Rollback plugin for WordPress contained both cross-site scripting and cross-site request forgery flaws that could be exploited by attackers. These vulnerabilities were present in versions before 1.2.3, where users could be targeted through malicious scripts or unauthorized actions performed on their behalf. The plugin developers addressed these security issues in version 1.2.3 and later releases.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings