Lucene search

K
cvelistMitreCVELIST:CVE-2014-5240
HistoryAug 18, 2014 - 10:00 a.m.

CVE-2014-5240

2014-08-1810:00:00
mitre
www.cve.org
6

AI Score

5.1

Confidence

High

EPSS

0.001

Percentile

36.4%

Cross-site scripting (XSS) vulnerability in wp-includes/pluggable.php in WordPress before 3.9.2, when Multisite is enabled, allows remote authenticated administrators to inject arbitrary web script or HTML, and obtain Super Admin privileges, via a crafted avatar URL.

AI Score

5.1

Confidence

High

EPSS

0.001

Percentile

36.4%