Unrated severityNVD Advisory· Published Jun 17, 2015· Updated May 6, 2026
CVE-2015-3429
CVE-2015-3429
Description
Cross-site scripting (XSS) vulnerability in example.html in Genericons before 3.3.1, as used in WordPress before 4.2.2, allows remote attackers to inject arbitrary web script or HTML via a fragment identifier.
Affected products
2- cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
12- seclists.org/fulldisclosure/2015/May/41nvdExploit
- www.digitalocean.com/community/tutorials/how-to-protect-your-wordpress-site-from-the-genericons-example-html-xss-vulnerabilitynvdExploit
- www.netsparker.com/cve-2015-3429-dom-xss-vulnerability-in-twenty-fifteen-wordpress-theme/nvdExploit
- lists.fedoraproject.org/pipermail/package-announce/2015-May/158271.htmlnvd
- lists.fedoraproject.org/pipermail/package-announce/2015-May/158278.htmlnvd
- packetstormsecurity.com/files/131802/WordPress-Twenty-Fifteen-4.2.1-Cross-Site-Scripting.htmlnvd
- www.debian.org/security/2015/dsa-3328nvd
- www.securityfocus.com/archive/1/535486/100/1000/threadednvd
- www.securityfocus.com/bid/74534nvd
- github.com/Automattic/Genericons/commit/798ac98579dd72dfdb11bdee3e7bebf01cffb1f7nvd
- wordpress.org/news/2015/05/wordpress-4-2-2/nvd
- wpvulndb.com/vulnerabilities/7965nvd
News mentions
0No linked articles in our index yet.