A cross-site scripting vulnerability in the Import Legacy Media plugin 0.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the filename parameter to getid3/demos/demo.mimeonly.php.
id: CVE-2014-4535
info:
name: Import Legacy Media <= 0.1 - Cross-Site Scripting
author: daffain
...