Alipay <= 3.6.0 'inc.tenpay_notify.php' Cross-Site Scripting (XSS)

Affects Plugin

fixed in version 3.7.0

References

CVE 2014-4514
SECURITYFOCUS 70695
URL http://codevigilant.com/disclosure/wp-plugin-alipay-a3-cross-site-scripting-xss/

Classification

Type XSS
OWASP Top 10 A7: Cross-Site Scripting (XSS)
CWE CWE-79

Miscellaneous

Submitter ethicalhack3r
Submitter Website https://dewhurstsecurity.com/
Submitter Twitter ethicalhack3r
Views 4016
Verified No
WPVDB ID 7649

Timeline

Publicly Published 2014-05-28 (over 5 years ago)
Added 2014-10-24 (almost 5 years ago)
Last Updated 2015-05-15 (over 4 years ago)

Our Other Services

Online WordPress Vulnerability Scanner WPScan WordPress Security Plugin