{"api_version":"1","generated_at":"2026-07-23T10:40:34+00:00","cve":"CVE-2015-3299","urls":{"html":"https://cve.report/CVE-2015-3299","api":"https://cve.report/api/cve/CVE-2015-3299.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2015-3299","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2015-3299"},"summary":{"title":"CVE-2015-3299","description":"Cross-site scripting (XSS) vulnerability in the Floating Social Bar plugin before 1.1.7 for WordPress allows remote attackers to inject arbitrary web script or HTML via vectors related to original service order.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2017-09-19 15:29:00","updated_at":"2017-09-25 21:27:00"},"problem_types":["CWE-79"],"metrics":[],"references":[{"url":"http://www.openwall.com/lists/oss-security/2015/04/13/10","name":"[oss-security] 20150413 Re: CVE request / Advisory: Floating Social Bar (Wordpress plugin) 1.0.1 - 1.1.6","refsource":"MLIST","tags":["Mailing List","Third Party Advisory"],"title":"oss-security - Re: CVE request / Advisory: Floating Social Bar (Wordpress plugin) 1.0.1 - 1.1.6","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://plugins.trac.wordpress.org/changeset/1129648/floating-social-bar/trunk","name":"https://plugins.trac.wordpress.org/changeset/1129648/floating-social-bar/trunk","refsource":"CONFIRM","tags":["Patch","Third Party Advisory"],"title":"403 Forbidden","mime":"text/html","httpstatus":"403","archivestatus":"403"},{"url":"http://www.securityfocus.com/bid/74053","name":"74053","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"WordPress Floating Social Bar Plugin CVE-2015-3299 HTML Injection Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2015-3299","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2015-3299","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2015","cve_id":"3299","vulnerable":"1","versionEndIncluding":"1.1.6","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"floating_social_bar_project","cpe5":"floating_social_bar","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"wordpress","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2015-3299","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in the Floating Social Bar plugin before 1.1.7 for WordPress allows remote attackers to inject arbitrary web script or HTML via vectors related to original service order."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"https://plugins.trac.wordpress.org/changeset/1129648/floating-social-bar/trunk","refsource":"CONFIRM","url":"https://plugins.trac.wordpress.org/changeset/1129648/floating-social-bar/trunk"},{"name":"74053","refsource":"BID","url":"http://www.securityfocus.com/bid/74053"},{"name":"[oss-security] 20150413 Re: CVE request / Advisory: Floating Social Bar (Wordpress plugin) 1.0.1 - 1.1.6","refsource":"MLIST","url":"http://www.openwall.com/lists/oss-security/2015/04/13/10"}]}},"nvd":{"publishedDate":"2017-09-19 15:29:00","lastModifiedDate":"2017-09-25 21:27:00","problem_types":["CWE-79"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":2.7},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":4.3},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:floating_social_bar_project:floating_social_bar:*:*:*:*:*:wordpress:*:*","versionEndIncluding":"1.1.6","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2015","CveId":"3299","Ordinal":"80252","Title":"CVE-2015-3299","CVE":"CVE-2015-3299","Year":"2015"},"notes":[{"CveYear":"2015","CveId":"3299","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in the Floating Social Bar plugin before 1.1.7 for WordPress allows remote attackers to inject arbitrary web script or HTML via vectors related to original service order.","Type":"Description","Title":null},{"CveYear":"2015","CveId":"3299","Ordinal":"2","NoteData":"2017-09-19","Type":"Other","Title":"Published"},{"CveYear":"2015","CveId":"3299","Ordinal":"3","NoteData":"2017-09-19","Type":"Other","Title":"Modified"}]}}}