CVE-2014-7958
Last modified
CVE-2014-7958 is a vulnerability of currently unknown severity. Cross-site scripting (XSS) vulnerability in admin/htaccess/bpsunlock.php in the BulletProof Security plugin before .51.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the dbhost parameter.. EPSS estimates a 2.51% chance of exploitation in the next 30 days.
Description
Cross-site scripting (XSS) vulnerability in admin/htaccess/bpsunlock.php in the BulletProof Security plugin before .51.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the dbhost parameter.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ait-Pro | Bulletproof Security | .44 |
| Ait-Pro | Bulletproof Security | .44.1 |
| Ait-Pro | Bulletproof Security | .45 |
| Ait-Pro | Bulletproof Security | .45.1 |
| Ait-Pro | Bulletproof Security | .45.2 |
| Ait-Pro | Bulletproof Security | .45.3 |
| Ait-Pro | Bulletproof Security | .45.4 |
| Ait-Pro | Bulletproof Security | .45.5 |
| Ait-Pro | Bulletproof Security | .45.6 |
| Ait-Pro | Bulletproof Security | .45.7 |
| Ait-Pro | Bulletproof Security | .45.8 |
| Ait-Pro | Bulletproof Security | .45.9 |
| Ait-Pro | Bulletproof Security | .46 |
| Ait-Pro | Bulletproof Security | .46.1 |
| Ait-Pro | Bulletproof Security | .46.2 |
| Ait-Pro | Bulletproof Security | .46.3 |
| Ait-Pro | Bulletproof Security | .46.4 |
| Ait-Pro | Bulletproof Security | .46.5 |
| Ait-Pro | Bulletproof Security | .46.6 |
| Ait-Pro | Bulletproof Security | .46.7 |
| Ait-Pro | Bulletproof Security | .46.8 |
| Ait-Pro | Bulletproof Security | .46.9 |
| Ait-Pro | Bulletproof Security | .47 |
| Ait-Pro | Bulletproof Security | .47.1 |
| Ait-Pro | Bulletproof Security | .47.2 |
| Ait-Pro | Bulletproof Security | .47.3 |
| Ait-Pro | Bulletproof Security | .47.4 |
| Ait-Pro | Bulletproof Security | .47.5 |
| Ait-Pro | Bulletproof Security | .47.6 |
| Ait-Pro | Bulletproof Security | .47.7 |
| Ait-Pro | Bulletproof Security | .47.8 |
| Ait-Pro | Bulletproof Security | .47.9 |
| Ait-Pro | Bulletproof Security | .48 |
| Ait-Pro | Bulletproof Security | .48.1 |
| Ait-Pro | Bulletproof Security | .48.2 |
| Ait-Pro | Bulletproof Security | .48.3 |
| Ait-Pro | Bulletproof Security | .48.4 |
| Ait-Pro | Bulletproof Security | .48.5 |
| Ait-Pro | Bulletproof Security | .48.6 |
| Ait-Pro | Bulletproof Security | .48.7 |
| Ait-Pro | Bulletproof Security | .48.8 |
| Ait-Pro | Bulletproof Security | .48.9 |
| Ait-Pro | Bulletproof Security | .49 |
| Ait-Pro | Bulletproof Security | .49.1 |
| Ait-Pro | Bulletproof Security | .49.2 |
| Ait-Pro | Bulletproof Security | .49.3 |
| Ait-Pro | Bulletproof Security | .49.4 |
| Ait-Pro | Bulletproof Security | .49.5 |
| Ait-Pro | Bulletproof Security | .49.6 |
| Ait-Pro | Bulletproof Security | .49.7 |
Showing 50 of 63 affected configurations. See NVD for the full list.
References
- http://packetstormsecurity.com/files/128977/WordPress-Bulletproof-Security-.51-XSS-SQL-Injection-SSRF.htmlExploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/533904/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/70916Third Party Advisory, VDB Entry
- https://wordpress.org/plugins/bulletproof-security/changelog/Patch, Vendor Advisory
- http://packetstormsecurity.com/files/128977/WordPress-Bulletproof-Security-.51-XSS-SQL-Injection-SSRF.htmlExploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/533904/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/70916Third Party Advisory, VDB Entry
- https://wordpress.org/plugins/bulletproof-security/changelog/Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-7958?
How severe is CVE-2014-7958?
How do I fix CVE-2014-7958?
Are you affected by CVE-2014-7958?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
