CVE-2014-4528
01.07.2014, 14:55
Multiple cross-site scripting (XSS) vulnerabilities in admin/swarm-settings.php in the Bugs Go Viral : Facebook Promotion Generator (fbpromotions) plugin 1.3.4 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) promo_type, (2) fb_edit_action, or (3) promo_id parameter.
Vendor | Product | Version |
---|---|---|
fbpromotions_project | fbpromotions | 𝑥 ≤ 1.3.4 |
𝑥
= Vulnerable software versions