01642 06 11 11 Arrange Call

Arbitrary Script Injection Vulnerability in BannerMan Plugin for WordPress

CVE-2014-4845 · MEDIUM

CVE-2014-4845

Cross-site scripting (XSS) vulnerability in the BannerMan plugin 0.2.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the bannerman_background parameter to wp-admin/options-general.php.

Learn more about our Wordpress Pen Testing.