{"api_version":"1","generated_at":"2026-07-23T05:22:54+00:00","cve":"CVE-2014-6315","urls":{"html":"https://cve.report/CVE-2014-6315","api":"https://cve.report/api/cve/CVE-2014-6315.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2014-6315","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2014-6315"},"summary":{"title":"CVE-2014-6315","description":"Multiple cross-site scripting (XSS) vulnerabilities in the Web-Dorado Photo Gallery plugin 1.1.30 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) callback, (2) dir, or (3) extensions parameter in an addImages action to wp-admin/admin-ajax.php.","state":"PUBLISHED","assigner":"mitre","published_at":"2014-10-10 14:55:08","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"https://plugins.trac.wordpress.org/changeset?new=986500","name":"https://plugins.trac.wordpress.org/changeset?new=986500","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"403 Forbidden","mime":"text/html","httpstatus":"403","archivestatus":"403"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/96799","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/96799","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/70204","name":"http://www.securityfocus.com/bid/70204","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"WordPress Photo Gallery Plugin 'admin-ajax.php' Multiple Cross Site Scripting Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://packetstormsecurity.com/files/128518/WordPress-Photo-Gallery-1.1.30-Cross-Site-Scripting.html","name":"http://packetstormsecurity.com/files/128518/WordPress-Photo-Gallery-1.1.30-Cross-Site-Scripting.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"WordPress Photo Gallery 1.1.30 Cross Site Scripting ≈ Packet Storm","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/533595/100/0/threaded","name":"http://www.securityfocus.com/archive/1/533595/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.htbridge.com/advisory/HTB23232","name":"https://www.htbridge.com/advisory/HTB23232","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"File Not Found","mime":"text/html","httpstatus":"404","archivestatus":"403"},{"url":"http://secunia.com/advisories/61649","name":"http://secunia.com/advisories/61649","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"About Secunia Research | Flexera","mime":"text/plain","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2014-6315","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2014-6315","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2014","cve_id":"6315","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"photo_gallery_plugin_project","cpe5":"photo_gallery_plugin","cpe6":"1.1.30","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"wordpress","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T12:10:13.333Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"70204","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/70204"},{"name":"20141001 Cross-Site Scripting (XSS) in Photo Gallery WordPress plugin","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/533595/100/0/threaded"},{"name":"wp-photogallery-cve20146315-xss(96799)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/96799"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://www.htbridge.com/advisory/HTB23232"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://packetstormsecurity.com/files/128518/WordPress-Photo-Gallery-1.1.30-Cross-Site-Scripting.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://plugins.trac.wordpress.org/changeset?new=986500"},{"name":"61649","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/61649"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2014-10-01T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple cross-site scripting (XSS) vulnerabilities in the Web-Dorado Photo Gallery plugin 1.1.30 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) callback, (2) dir, or (3) extensions parameter in an addImages action to wp-admin/admin-ajax.php."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-09T18:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"70204","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/70204"},{"name":"20141001 Cross-Site Scripting (XSS) in Photo Gallery WordPress plugin","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/533595/100/0/threaded"},{"name":"wp-photogallery-cve20146315-xss(96799)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/96799"},{"tags":["x_refsource_MISC"],"url":"https://www.htbridge.com/advisory/HTB23232"},{"tags":["x_refsource_MISC"],"url":"http://packetstormsecurity.com/files/128518/WordPress-Photo-Gallery-1.1.30-Cross-Site-Scripting.html"},{"tags":["x_refsource_CONFIRM"],"url":"https://plugins.trac.wordpress.org/changeset?new=986500"},{"name":"61649","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/61649"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2014-6315","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple cross-site scripting (XSS) vulnerabilities in the Web-Dorado Photo Gallery plugin 1.1.30 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) callback, (2) dir, or (3) extensions parameter in an addImages action to wp-admin/admin-ajax.php."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"70204","refsource":"BID","url":"http://www.securityfocus.com/bid/70204"},{"name":"20141001 Cross-Site Scripting (XSS) in Photo Gallery WordPress plugin","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/533595/100/0/threaded"},{"name":"wp-photogallery-cve20146315-xss(96799)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/96799"},{"name":"https://www.htbridge.com/advisory/HTB23232","refsource":"MISC","url":"https://www.htbridge.com/advisory/HTB23232"},{"name":"http://packetstormsecurity.com/files/128518/WordPress-Photo-Gallery-1.1.30-Cross-Site-Scripting.html","refsource":"MISC","url":"http://packetstormsecurity.com/files/128518/WordPress-Photo-Gallery-1.1.30-Cross-Site-Scripting.html"},{"name":"https://plugins.trac.wordpress.org/changeset?new=986500","refsource":"CONFIRM","url":"https://plugins.trac.wordpress.org/changeset?new=986500"},{"name":"61649","refsource":"SECUNIA","url":"http://secunia.com/advisories/61649"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2014-6315","datePublished":"2014-10-10T14:00:00.000Z","dateReserved":"2014-09-11T00:00:00.000Z","dateUpdated":"2024-08-06T12:10:13.333Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2014-10-10 14:55:08","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:photo_gallery_plugin_project:photo_gallery_plugin:1.1.30:*:*:*:*:wordpress:*:*","matchCriteriaId":"A9CEE5B7-CF07-4DC4-9441-AA3E9A3E3319"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2014","CveId":"6315","Ordinal":"1","Title":"CVE-2014-6315","CVE":"CVE-2014-6315","Year":"2014"},"notes":[{"CveYear":"2014","CveId":"6315","Ordinal":"1","NoteData":"Multiple cross-site scripting (XSS) vulnerabilities in the Web-Dorado Photo Gallery plugin 1.1.30 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) callback, (2) dir, or (3) extensions parameter in an addImages action to wp-admin/admin-ajax.php.","Type":"Description","Title":"CVE-2014-6315"},{"CveYear":"2014","CveId":"6315","Ordinal":"2","NoteData":"2014-10-10","Type":"Other","Title":"Published"},{"CveYear":"2014","CveId":"6315","Ordinal":"3","NoteData":"2018-10-09","Type":"Other","Title":"Modified"}]}}}