CVE-2014-2315
Multiple cross-site scripting (XSS) vulnerabilities in the Thank You Counter Button plugin 1.8.7 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) thanks_caption, (2) thanks_caption_style, or (3) thanks_style parameter to wp-admin/options.php.
View on NVDSeverity
N/A
EPSS
Probability of exploitation (next 30 days): 0.0027 (0.3%)
Percentile: 50.3%
EPSS: 2026-05-06
Affects
shinephp:thank_you_counter_buttonwordpress:wordpressTechnical description
Multiple cross-site scripting (XSS) vulnerabilities in the Thank You Counter Button plugin 1.8.7 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) thanks_caption, (2) thanks_caption_style, or (3) thanks_style parameter to wp-admin/options.php.
Published: 3/9/2014, 1:16:57 PM
Last modified: 5/6/2026, 10:30:45 PM