ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

1 result for “CVE-2016-9263”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2016-9263
Published
2017-10-12
CVSS:
4.7
ShadowTrackr CVSS:
1.2
Summary:
WordPress through 4.8.2, when domain-based flashmediaelement.swf sandboxing is not used, allows remote attackers to conduct cross-domain Flash injection (XSF) attacks by leveraging code contained within the wp-includes/js/mediaelement/flashmediaelement.swf file.