CVE-2014-5202: Compfight Project Compfight

Low severity, CVSS 3.5. EPSS: 1.5% chance of exploitation in the next 30 days.

Cross-site scripting (XSS) vulnerability in compfight-search.php in the Compfight plugin 1.4 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the search-value parameter.

Affected products

Published 2014-08-12. Last modified 2026-06-17.