CVE-2014-8800 | Nextend Facebook Connect prior 1.5.0 nextend-facebook-settings.php fb_login_button cross site scripting (EDB-35439 / OSVDB-115231)
A vulnerability was found in Nextend Facebook Connect. It has been rated as problematic. This issue affects some unknown processing of the file nextend-facebook-settings.php. The manipulation of the argument fb_login_button leads to cross site scripting.
The identification of this vulnerability is CVE-2014-8800. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.