peter bassill · operator
$ cve CVE-2015-1494 JSON

CVE-2015-1494 EXPLOIT

4.3
MEDIUM · CVSS 2.0 · EPSS 6.4% (pctl 93)

Patch early

A public exploit exists.

Description

The FancyBox for WordPress plugin before 3.0.3 for WordPress does not properly restrict access, which allows remote attackers to conduct cross-site scripting (XSS) attacks via an mfbfw[*] parameter in an update action to wp-admin/admin-post.php, as demonstrated by the mfbfw[padding] parameter and exploited in the wild in February 2015.

Scoring

CVSS4.3 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS6.41% — more likely to be exploited than 93% of all CVEs
WeaknessCWE-79
On CISA KEVno
Public exploityes
Published2015-02-17
Last modified2026-06-17

Affected (1)

VendorProduct
colorlibfancybox

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD