Unrated severityNVD Advisory· Published Jan 13, 2015· Updated May 6, 2026
CVE-2014-100018
CVE-2014-100018
Description
Cross-site scripting (XSS) vulnerability in the Unconfirmed plugin before 1.2.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter in the unconfirmed page to wp-admin/network/users.php.
Affected products
1- cpe:2.3:a:unconfirmed_project:unconfirmed:*:*:*:*:*:wordpress:*:*Range: <=1.2.4
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4News mentions
0No linked articles in our index yet.