|Description||Plupload before 1.5.4, as used in wp-includes/js/plupload/ in WordPress before 3.3.2 and other products, enables scripting regardless of the domain from which the SWF content was loaded, which allows remote attackers to bypass the Same Origin Policy via crafted content.|
|Source||CVE (at NVD; LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)|
|NVD severity||medium (attack range: remote)|
Vulnerable and fixed packages
The table below lists information on source packages.
|wordpress (PTS)||wheezy (security), wheezy||3.6.1+dfsg-1~deb7u10||fixed|
|jessie (security), jessie||4.1+dfsg-1+deb8u8||fixed|
The information below is based on the following data on fixed versions.