CVE-2014-9094 EXPLOIT
4.3
MEDIUM · CVSS 2.0 · EPSS 7.3% (pctl 94)
Patch early
A public exploit exists.
Description
Multiple cross-site scripting (XSS) vulnerabilities in deploy/designer/preview.php in the Digital Zoom Studio (DZS) Video Gallery plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) swfloc or (2) designrand parameter.
Scoring
| CVSS | 4.3 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
| EPSS | 7.31% — more likely to be exploited than 94% of all CVEs |
| Weakness | CWE-79 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2014-11-26 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| digitalzoomstudio | video gallery |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | WordPress Plugin DZS-VideoGallery - Cross-Site Scripting / Command Injection | 2014-07-13 |
References
- http://seclists.org/fulldisclosure/2014/Jul/65
- http://websecurity.com.ua/7152/
- http://www.securityfocus.com/bid/108579
- http://www.securityfocus.com/bid/68525
- http://seclists.org/fulldisclosure/2014/Jul/65
- http://websecurity.com.ua/7152/
- http://www.securityfocus.com/bid/108579
- http://www.securityfocus.com/bid/68525
→ the Explorer · watch your stack · NVD