← Back to CVE List

CVE-2015-7357

Published: 2017-10-03T01:29Z
Last Modified: 2024-11-21T02:36Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Cross-site scripting (XSS) vulnerability in the uDesign (aka U-Design) theme 2.3.0 before 2.7.10 for WordPress allows remote attackers to inject arbitrary web script or HTML via a fragment identifier, as demonstrated by #<svg onload=alert(1)>. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt