Vigil@nce - WordPress Conversionninja: Cross Site Scripting

This bulletin was written by Vigil@nce : http://vigilance.fr/offer

SYNTHESIS OF THE VULNERABILITY

An attacker can trigger a Cross Site Scripting of WordPress
Conversionninja, in order to execute JavaScript code in the
context of the web site.

Impacted products: WordPress Plugins

Severity: 2/4

Creation date: 23/05/2014

DESCRIPTION OF THE VULNERABILITY

The Conversionninja plugin can be installed on WordPress.

However, it does not filter received data before inserting them in
generated HTML documents.

An attacker can therefore trigger a Cross Site Scripting of
WordPress Conversionninja, in order to execute JavaScript code in
the context of the web site.

ACCESS TO THE COMPLETE VIGIL@NCE BULLETIN

http://vigilance.fr/vulnerability/WordPress-Conversionninja-Cross-Site-Scripting-14795

Articles similaires

Security Vulnerability

21 September 2026

Vigilance.fr - Linux kernel: nine vulnerabilities dated 21/07/2026

An attacker can use several vulnerabilities of the Linux kernel, dated 21/07/2026.

Security Vulnerability

20 September 2026

Vigilance.fr - RSYSLOG: buffer overflow via mmpstrucdata, analyzed on 20/07/2026

An attacker can trigger a buffer overflow of RSYSLOG, via mmpstrucdata, in order to trigger a (…)

Security Vulnerability

20 September 2026

Vigilance.fr - Linux kernel: multiple vulnerabilities dated 20/07/2026

An attacker can use several vulnerabilities of the Linux kernel, dated 20/07/2026.