CVE-2015-3439
published 2015-08-05CVE-2015-3439: Cross-site scripting (XSS) vulnerability in the Ephox (formerly Moxiecode) plupload.flash.swf shim 2.1.2 in Plupload, as used in WordPress 3.9.x, 4.0.x, and…
PriorityP425medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
6.12%
92.6th percentile
Cross-site scripting (XSS) vulnerability in the Ephox (formerly Moxiecode) plupload.flash.swf shim 2.1.2 in Plupload, as used in WordPress 3.9.x, 4.0.x, and 4.1.x before 4.1.2 and other products, allows remote attackers to execute same-origin JavaScript functions via the target parameter, as demonstrated by executing a certain click function, related to _init.as and _fireEvent.as.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | wordpress | < wordpress 4.2+dfsg-1 (bookworm) | wordpress 4.2+dfsg-1 (bookworm) |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | >= 0 < 4.2+dfsg-1 | 4.2+dfsg-1 |
| wordpress | wordpress | >= 0 < 4.2+dfsg-1 | 4.2+dfsg-1 |
| wordpress | wordpress | >= 0 < 4.2+dfsg-1 | 4.2+dfsg-1 |
| wordpress | wordpress | >= 0 < 4.2+dfsg-1 | 4.2+dfsg-1 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2015-3439: wordpress - Cross-site scripting (XSS) vulnerability in the Ephox (formerly Moxiecode) plupl...
vendor_debian·2015·CVSS 4.3
CVE-2015-3439 [MEDIUM] CVE-2015-3439: wordpress - Cross-site scripting (XSS) vulnerability in the Ephox (formerly Moxiecode) plupl...
Cross-site scripting (XSS) vulnerability in the Ephox (formerly Moxiecode) plupload.flash.swf shim 2.1.2 in Plupload, as used in WordPress 3.9.x, 4.0.x, and 4.1.x before 4.1.2 and other products, allows remote attackers to execute same-origin JavaScript functions via the target parameter, as demonstrated by executing a certain click function, related to _init.as and _fireEvent.as.
Scope: local
bookworm: resolved (fixed in 4.2+dfsg-1)
bullseye: resolved (fixed in 4.2+dfsg-1)
forky: resolved (fixed in 4.2+dfsg-1)
sid: resolved (fixed in 4.2+dfsg-1)
trixie: resolved (fixed in 4.2+dfsg-1)
GHSA
GHSA-wfch-pm8w-hchp: Cross-site scripting (XSS) vulnerability in the Ephox (formerly Moxiecode) plupload
ghsa_unreviewed·2022-05-17
CVE-2015-3439 [MEDIUM] CWE-79 GHSA-wfch-pm8w-hchp: Cross-site scripting (XSS) vulnerability in the Ephox (formerly Moxiecode) plupload
Cross-site scripting (XSS) vulnerability in the Ephox (formerly Moxiecode) plupload.flash.swf shim 2.1.2 in Plupload, as used in WordPress 3.9.x, 4.0.x, and 4.1.x before 4.1.2 and other products, allows remote attackers to execute same-origin JavaScript functions via the target parameter, as demonstrated by executing a certain click function, related to _init.as and _fireEvent.as.
OSV
CVE-2015-3439: Cross-site scripting (XSS) vulnerability in the Ephox (formerly Moxiecode) plupload
osv·2015-08-05·CVSS 4.3
CVE-2015-3439 [MEDIUM] CVE-2015-3439: Cross-site scripting (XSS) vulnerability in the Ephox (formerly Moxiecode) plupload
Cross-site scripting (XSS) vulnerability in the Ephox (formerly Moxiecode) plupload.flash.swf shim 2.1.2 in Plupload, as used in WordPress 3.9.x, 4.0.x, and 4.1.x before 4.1.2 and other products, allows remote attackers to execute same-origin JavaScript functions via the target parameter, as demonstrated by executing a certain click function, related to _init.as and _fireEvent.as.
No detection rules found.
No public exploits indexed.
http://codex.wordpress.org/Version_4.1.2http://lists.fedoraproject.org/pipermail/package-announce/2015-May/157391.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-May/158271.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-May/158278.htmlhttp://www.debian.org/security/2015/dsa-3250http://www.securityfocus.com/bid/74269http://www.securitytracker.com/id/1032207http://zoczus.blogspot.com/2015/04/plupload-same-origin-method-execution.htmlhttps://core.trac.wordpress.org/changeset/32168https://wordpress.org/news/2015/04/wordpress-4-1-2/https://wpvulndb.com/vulnerabilities/7933http://codex.wordpress.org/Version_4.1.2http://lists.fedoraproject.org/pipermail/package-announce/2015-May/157391.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-May/158271.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-May/158278.htmlhttp://www.debian.org/security/2015/dsa-3250http://www.securityfocus.com/bid/74269http://www.securitytracker.com/id/1032207http://zoczus.blogspot.com/2015/04/plupload-same-origin-method-execution.htmlhttps://core.trac.wordpress.org/changeset/32168https://wordpress.org/news/2015/04/wordpress-4-1-2/https://wpvulndb.com/vulnerabilities/7933
2015-08-05
Published