Unrated severityNVD Advisory· Published Jan 8, 2014· Updated Apr 29, 2026
CVE-2014-1232
CVE-2014-1232
Description
Cross-site scripting (XSS) vulnerability in the Foliopress WYSIWYG plugin before 2.6.8.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected products
5cpe:2.3:a:foliovision:foliopress_wysiwyg:*:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:foliovision:foliopress_wysiwyg:*:*:*:*:*:*:*:*range: <=2.6.8.4
- cpe:2.3:a:foliovision:foliopress_wysiwyg:2.6.8:*:*:*:*:*:*:*
- cpe:2.3:a:foliovision:foliopress_wysiwyg:2.6.8.1:*:*:*:*:*:*:*
- cpe:2.3:a:foliovision:foliopress_wysiwyg:2.6.8.2:*:*:*:*:*:*:*
- cpe:2.3:a:foliovision:foliopress_wysiwyg:2.6.8.3:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- wordpress.org/plugins/foliopress-wysiwyg/changelognvdPatchVendor Advisory
- secunia.com/advisories/56261nvdVendor Advisory
- www.securityfocus.com/bid/64666nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/90102nvd
News mentions
0No linked articles in our index yet.