01642 06 11 11 Arrange Call

Arbitrary Web Script Injection via title parameter in SS Downloads Plugin for WordPress

CVE-2014-4554 · MEDIUM

CVE-2014-4554

Cross-site scripting (XSS) vulnerability in templates/download.php in the SS Downloads plugin before 1.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the title parameter.

Learn more about our Wordpress Pen Testing.