CVE-2014-7958

medium
Published 2014-11-06 ยท Modified 2026-05-06
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
4.3

Description

Cross-site scripting (XSS) vulnerability in admin/htaccess/bpsunlock.php in the BulletProof Security plugin before .51.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the dbhost parameter.

Predictions

Exploit likelihood
20%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ€” if you've already worked around this in production โ€” publish your fix to the community-verified tier.

โœš Propose a mitigation on Community โ†’ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

Application impact

VendorProductVersionsFixed
ait-probulletproof_security.44
ait-probulletproof_security.44.1
ait-probulletproof_security.45
ait-probulletproof_security.45.1
ait-probulletproof_security.45.2
ait-probulletproof_security.45.3
ait-probulletproof_security.45.4
ait-probulletproof_security.45.5
ait-probulletproof_security.45.6
ait-probulletproof_security.45.7
ait-probulletproof_security.45.8
ait-probulletproof_security.45.9
ait-probulletproof_security.46
ait-probulletproof_security.46.1
ait-probulletproof_security.46.2
ait-probulletproof_security.46.3
ait-probulletproof_security.46.4
ait-probulletproof_security.46.5
ait-probulletproof_security.46.6
ait-probulletproof_security.46.7
ait-probulletproof_security.46.8
ait-probulletproof_security.46.9
ait-probulletproof_security.47
ait-probulletproof_security.47.1
ait-probulletproof_security.47.2
ait-probulletproof_security.47.3
ait-probulletproof_security.47.4
ait-probulletproof_security.47.5
ait-probulletproof_security.47.6
ait-probulletproof_security.47.7
ait-probulletproof_security.47.8
ait-probulletproof_security.47.9
ait-probulletproof_security.48
ait-probulletproof_security.48.1
ait-probulletproof_security.48.2
ait-probulletproof_security.48.3
ait-probulletproof_security.48.4
ait-probulletproof_security.48.5
ait-probulletproof_security.48.6
ait-probulletproof_security.48.7
ait-probulletproof_security.48.8
ait-probulletproof_security.48.9
ait-probulletproof_security.49
ait-probulletproof_security.49.1
ait-probulletproof_security.49.2
ait-probulletproof_security.49.3
ait-probulletproof_security.49.4
ait-probulletproof_security.49.5
ait-probulletproof_security.49.6
ait-probulletproof_security.49.7
ait-probulletproof_security.49.8
ait-probulletproof_security.49.9
ait-probulletproof_security.50
ait-probulletproof_security.50.1
ait-probulletproof_security.50.2
ait-probulletproof_security.50.3
ait-probulletproof_security.50.4
ait-probulletproof_security.50.5
ait-probulletproof_security.50.6
ait-probulletproof_security.50.7
ait-probulletproof_security.50.8
ait-probulletproof_security.50.9
ait-probulletproof_security.51

References

CWEs

CWE-79

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.