CVE-2015-3439
Last modified
CVE-2015-3439 is a vulnerability of currently unknown severity. Cross-site scripting (XSS) vulnerability in the Ephox (formerly Moxiecode) plupload.flash.swf shim 2.1.2 in Plupload, as used in WordPress 3.9.x, 4.0.x, and 4.1.x before 4.1.2 and other products, allows remote attackers to execute same-origin JavaScript functions via the target parameter, as demonstrated by executing a certain click function, related to _init.as and _fireEvent.as.. EPSS estimates a 6.04% chance of exploitation in the next 30 days.
Description
Cross-site scripting (XSS) vulnerability in the Ephox (formerly Moxiecode) plupload.flash.swf shim 2.1.2 in Plupload, as used in WordPress 3.9.x, 4.0.x, and 4.1.x before 4.1.2 and other products, allows remote attackers to execute same-origin JavaScript functions via the target parameter, as demonstrated by executing a certain click function, related to _init.as and _fireEvent.as.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Debian | Debian Linux | 7.0 |
| Debian | Debian Linux | 8.0 |
| Wordpress | Wordpress | 3.9.0 |
| Wordpress | Wordpress | 3.9.1 |
| Wordpress | Wordpress | 3.9.2 |
| Wordpress | Wordpress | 3.9.3 |
| Wordpress | Wordpress | 4.0 |
| Wordpress | Wordpress | 4.0.1 |
| Wordpress | Wordpress | 4.1 |
| Wordpress | Wordpress | 4.1.1 |
References
- http://codex.wordpress.org/Version_4.1.2Exploit, Patch
- https://wordpress.org/news/2015/04/wordpress-4-1-2/Exploit, Vendor Advisory
- http://codex.wordpress.org/Version_4.1.2Exploit, Patch
- https://wordpress.org/news/2015/04/wordpress-4-1-2/Exploit, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-3439?
How severe is CVE-2015-3439?
How do I fix CVE-2015-3439?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2015
- CVE-2015-3429Cross-site scripting (XSS) vulnerability in example.html in …
- CVE-2015-3431Pydio (formerly AjaXplorer) before 6.0.7 allows remote attac…
- CVE-2015-3432Multiple cross-site scripting (XSS) vulnerabilities in Pydio…
- CVE-2015-3435Samsung Security Manager (SSM) before 1.31 allows remote att…
- CVE-2015-3436provider/server/ECServer.cpp in Zarafa Collaboration Platfor…
- CVE-2015-3438Multiple cross-site scripting (XSS) vulnerabilities in WordP…
- CVE-2015-3440Cross-site scripting (XSS) vulnerability in wp-includes/wp-d…
- CVE-2015-3441The Parental Control panel in Genexis devices with DRGOS bef…
- CVE-2015-3442Soreco Xpert.Line 3.0 allows local users to spoof users and …
- CVE-2015-3443Cross-site scripting (XSS) vulnerability in the basic dashbo…
- CVE-2015-3446The Framework Daemon in AlienVault Unified Security Manageme…
- CVE-2015-3447Multiple cross-site scripting (XSS) vulnerabilities in macIp…
Are you affected by CVE-2015-3439?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
