CVE-2015-9424
26.09.2019, 01:15
The multicons plugin before 3.0 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page=multicons%2Fmulticons.php global_url or admin_url parameter.
Vendor | Product | Version |
---|---|---|
doc4design | multicons | 𝑥 < 3.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References