A cross-site scripting vulnerability in the Movies plugin 0.6 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the filename parameter to getid3/demos/demo.mimeonly.php.
id: CVE-2014-4539
info:
name: Movies <= 0.6 - Cross-Site Scripting
author: daffainfo
severity
...