Publicly exploitable XSS in WordPress plugin Navis Documentcloud (WordPress plugin)

Posted by dxw Security on Aug 27

Details
================
Software: Navis DocumentCloud
Version: 0.1
Homepage: https://wordpress.org/plugins/navis-documentcloud/
Advisory report: https://security.dxw.com/advisories/publicly-exploitable-xss-in-wordpress-plugin-navis-documentcloud/
CVE: CVE-2015-2807
CVSS: 6.4 (Medium; AV:N/AC:L/Au:N/C:P/I:P/A:N)

Description
================
Publicly exploitable XSS in WordPress plugin Navis Documentcloud

Vulnerability
================
This…

Leave a Reply