CVE-2014-9031

Source
https://nvd.nist.gov/vuln/detail/CVE-2014-9031
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2014-9031.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2014-9031
Downstream
Related
Published
2014-11-25T23:59:01Z
Modified
2025-08-09T20:01:26Z
Summary
[none]
Details

Cross-site scripting (XSS) vulnerability in the wptexturize function in WordPress before 3.7.5, 3.8.x before 3.8.5, and 3.9.x before 3.9.3 allows remote attackers to inject arbitrary web script or HTML via crafted use of shortcode brackets in a text field, as demonstrated by a comment or a post.

References

Affected packages