CVE-2015-9453

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
07/10/2019
Last modified:
10/10/2019

Description

The broken-link-manager plugin before 0.6.0 for WordPress has XSS via the HTTP Referer or User-Agent header to a URL that does not exist.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:k-78:broken_link_manager:*:*:*:*:*:wordpress:*:* 0.6.0 (excluding)