Medium severity6.1NVD Advisory· Published Dec 27, 2019· Updated Jun 17, 2026
CVE-2014-4548
CVE-2014-4548
Description
Cross-site scripting (XSS) vulnerability in tinymce/popup.php in the Ruven Toolkit plugin 1.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the popup parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:ruven-toolkit_project:ruven-toolkit:*:*:*:*:*:wordpress:*:*Range: <=1.1
- WordPress/Ruven Toolkit plugindescription
- Range: <=1.1
Patches
Vulnerability mechanics
References
1- codevigilant.com/disclosure/wp-plugin-ruven-toolkit-a3-cross-site-scripting-xssnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.