CVE-2015-9424
EUVD-2015-926426.09.2019, 01:15
The multicons plugin before 3.0 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page=multicons%2Fmulticons.php global_url or admin_url parameter.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| doc4design | multicons | 𝑥 < 3.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References