CVE-2015-7357

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
03/10/2017
Last modified:
20/04/2025

Description

Cross-site scripting (XSS) vulnerability in the uDesign (aka U-Design) theme 2.3.0 before 2.7.10 for WordPress allows remote attackers to inject arbitrary web script or HTML via a fragment identifier, as demonstrated by #.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:udesign_project:udesign:2.3.0:*:*:*:*:wordpress:*:*
cpe:2.3:a:udesign_project:udesign:2.3.1:*:*:*:*:wordpress:*:*
cpe:2.3:a:udesign_project:udesign:2.4.0:*:*:*:*:wordpress:*:*
cpe:2.3:a:udesign_project:udesign:2.4.1:*:*:*:*:wordpress:*:*
cpe:2.3:a:udesign_project:udesign:2.4.2:*:*:*:*:wordpress:*:*
cpe:2.3:a:udesign_project:udesign:2.4.3:*:*:*:*:wordpress:*:*
cpe:2.3:a:udesign_project:udesign:2.4.4:*:*:*:*:wordpress:*:*
cpe:2.3:a:udesign_project:udesign:2.4.5:*:*:*:*:wordpress:*:*
cpe:2.3:a:udesign_project:udesign:2.4.6:*:*:*:*:wordpress:*:*
cpe:2.3:a:udesign_project:udesign:2.4.7:*:*:*:*:wordpress:*:*
cpe:2.3:a:udesign_project:udesign:2.4.8:*:*:*:*:wordpress:*:*
cpe:2.3:a:udesign_project:udesign:2.4.9:*:*:*:*:wordpress:*:*
cpe:2.3:a:udesign_project:udesign:2.4.10:*:*:*:*:wordpress:*:*
cpe:2.3:a:udesign_project:udesign:2.4.11:*:*:*:*:wordpress:*:*
cpe:2.3:a:udesign_project:udesign:2.4.12:*:*:*:*:wordpress:*:*