CVE-2014-7958
Last modified
CVE-2014-7958 is a vulnerability of currently unknown severity. Cross-site scripting (XSS) vulnerability in admin/htaccess/bpsunlock.php in the BulletProof Security plugin before .51.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the dbhost parameter.. EPSS estimates a 2.51% chance of exploitation in the next 30 days.
Description
Cross-site scripting (XSS) vulnerability in admin/htaccess/bpsunlock.php in the BulletProof Security plugin before .51.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the dbhost parameter.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ait-Pro | Bulletproof Security | .44 |
| Ait-Pro | Bulletproof Security | .44.1 |
| Ait-Pro | Bulletproof Security | .45 |
| Ait-Pro | Bulletproof Security | .45.1 |
| Ait-Pro | Bulletproof Security | .45.2 |
| Ait-Pro | Bulletproof Security | .45.3 |
| Ait-Pro | Bulletproof Security | .45.4 |
| Ait-Pro | Bulletproof Security | .45.5 |
| Ait-Pro | Bulletproof Security | .45.6 |
| Ait-Pro | Bulletproof Security | .45.7 |
| Ait-Pro | Bulletproof Security | .45.8 |
| Ait-Pro | Bulletproof Security | .45.9 |
| Ait-Pro | Bulletproof Security | .46 |
| Ait-Pro | Bulletproof Security | .46.1 |
| Ait-Pro | Bulletproof Security | .46.2 |
| Ait-Pro | Bulletproof Security | .46.3 |
| Ait-Pro | Bulletproof Security | .46.4 |
| Ait-Pro | Bulletproof Security | .46.5 |
| Ait-Pro | Bulletproof Security | .46.6 |
| Ait-Pro | Bulletproof Security | .46.7 |
| Ait-Pro | Bulletproof Security | .46.8 |
| Ait-Pro | Bulletproof Security | .46.9 |
| Ait-Pro | Bulletproof Security | .47 |
| Ait-Pro | Bulletproof Security | .47.1 |
| Ait-Pro | Bulletproof Security | .47.2 |
| Ait-Pro | Bulletproof Security | .47.3 |
| Ait-Pro | Bulletproof Security | .47.4 |
| Ait-Pro | Bulletproof Security | .47.5 |
| Ait-Pro | Bulletproof Security | .47.6 |
| Ait-Pro | Bulletproof Security | .47.7 |
| Ait-Pro | Bulletproof Security | .47.8 |
| Ait-Pro | Bulletproof Security | .47.9 |
| Ait-Pro | Bulletproof Security | .48 |
| Ait-Pro | Bulletproof Security | .48.1 |
| Ait-Pro | Bulletproof Security | .48.2 |
| Ait-Pro | Bulletproof Security | .48.3 |
| Ait-Pro | Bulletproof Security | .48.4 |
| Ait-Pro | Bulletproof Security | .48.5 |
| Ait-Pro | Bulletproof Security | .48.6 |
| Ait-Pro | Bulletproof Security | .48.7 |
| Ait-Pro | Bulletproof Security | .48.8 |
| Ait-Pro | Bulletproof Security | .48.9 |
| Ait-Pro | Bulletproof Security | .49 |
| Ait-Pro | Bulletproof Security | .49.1 |
| Ait-Pro | Bulletproof Security | .49.2 |
| Ait-Pro | Bulletproof Security | .49.3 |
| Ait-Pro | Bulletproof Security | .49.4 |
| Ait-Pro | Bulletproof Security | .49.5 |
| Ait-Pro | Bulletproof Security | .49.6 |
| Ait-Pro | Bulletproof Security | .49.7 |
Showing 50 of 63 affected configurations. See NVD for the full list.
References
- http://packetstormsecurity.com/files/128977/WordPress-Bulletproof-Security-.51-XSS-SQL-Injection-SSRF.htmlExploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/533904/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/70916Third Party Advisory, VDB Entry
- https://wordpress.org/plugins/bulletproof-security/changelog/Patch, Vendor Advisory
- http://packetstormsecurity.com/files/128977/WordPress-Bulletproof-Security-.51-XSS-SQL-Injection-SSRF.htmlExploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/533904/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/70916Third Party Advisory, VDB Entry
- https://wordpress.org/plugins/bulletproof-security/changelog/Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-7958?
How severe is CVE-2014-7958?
How do I fix CVE-2014-7958?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2014
- CVE-2014-7951Directory traversal vulnerability in the Android debug bridg…4.6
- CVE-2014-7952The backup mechanism in the adb tool in Android might allow …
- CVE-2014-7953Race condition in the bindBackupAgent method in the Activity…
- CVE-2014-7954Directory traversal vulnerability in the doSendObjectInfo me…
- CVE-2014-7956Cross-site scripting (XSS) vulnerability in the Pods plugin …
- CVE-2014-7957Multiple cross-site request forgery (CSRF) vulnerabilities i…
- CVE-2014-7959SQL injection vulnerability in admin/htaccess/bpsunlock.php …
- CVE-2014-7960OpenStack Object Storage (Swift) before 2.2.0 allows remote …
- CVE-2014-7967Multiple unspecified vulnerabilities in Google V8 before 3.2…
- CVE-2014-7968VDSM allows remote attackers to cause a denial of service (c…
- CVE-2014-7969Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2014-7970The pivot_root implementation in fs/namespace.c in the Linux…5.5
Are you affected by CVE-2014-7958?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
