CVE

CVE-2014-4855 — Polylang [polylang] < 1.5.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2014-4855 Polylang [polylang] < 1.5.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Unknown < 1.5.2 1.5.2 2014-07-10

CVE-2014-4855

The Polylang plugin for WordPress before version 1.5.2 contains a cross-site scripting vulnerability that permits attackers to inject malicious scripts or HTML code through the user description field. This flaw allows remote attackers to execute arbitrary code in the context of affected users' browsers.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.