CVE-2015-3439
Summary
| CVE | CVE-2015-3439 |
|---|---|
| State | PUBLISHED |
| Assigner | debian |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-08-05 10:59:00 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | Cross-site scripting (XSS) vulnerability in the Ephox (formerly Moxiecode) plupload.flash.swf shim 2.1.2 in Plupload, as used in WordPress 3.9.x, 4.0.x, and 4.1.x before 4.1.2 and other products, allows remote attackers to execute same-origin JavaScript functions via the target parameter, as demonstrated by executing a certain click function, related to _init.as and _fireEvent.as. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 7.0 | All | All | All |
| Operating System | Debian | Debian Linux | 8.0 | All | All | All |
| Application | Wordpress | Wordpress | 3.9.0 | All | All | All |
| Application | Wordpress | Wordpress | 3.9.1 | All | All | All |
| Application | Wordpress | Wordpress | 3.9.2 | All | All | All |
| Application | Wordpress | Wordpress | 3.9.3 | All | All | All |
| Application | Wordpress | Wordpress | 4.0 | All | All | All |
| Application | Wordpress | Wordpress | 4.0.1 | All | All | All |
| Application | Wordpress | Wordpress | 4.1 | All | All | All |
| Application | Wordpress | Wordpress | 4.1.1 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| WordPress Multiple Security Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| [SECURITY] Fedora 22 Update: wordpress-4.2.1-1.fc22 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| Version 4.1.2 « WordPress Codex | af854a3a-2127-422b-91ae-364da2661108 | codex.wordpress.org | Exploit, Patch |
| [SECURITY] Fedora 21 Update: wordpress-4.2.2-1.fc21 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| WordPress › WordPress 4.1.2 Security Release | af854a3a-2127-422b-91ae-364da2661108 | wordpress.org | Exploit, Vendor Advisory |
| ZoczuS Blog: plupload - Same-Origin Method Execution [Wordpress 3.9 - 4.1.1] | af854a3a-2127-422b-91ae-364da2661108 | zoczus.blogspot.com | Exploit |
| Changeset 32168 – WordPress Trac | af854a3a-2127-422b-91ae-364da2661108 | core.trac.wordpress.org | |
| Debian -- Security Information -- DSA-3250-1 wordpress | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| WordPress Input Validation Flaws Permit Cross-Site Scripting and SQL Injection Attacks - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| [SECURITY] Fedora 20 Update: wordpress-4.2.2-1.fc20 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| WordPress 3.9-4.1.1 - Same-Origin Method Execution | af854a3a-2127-422b-91ae-364da2661108 | wpvulndb.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.