CVE-2015-1494

EXPLOITED IN THE WILD

FancyBox for WordPress <3.0.3 - XSS

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2015-1494 has been observed exploited in the wild (reported by VulnCheck KEV, InTheWild.io). EIP tracks 1 public exploit from researchers including NULLpOint7r.

AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in the WordPress plugin Fancybox-for-WordPress (version 3.0.2). The vulnerability arises due to insufficient sanitization of user input in the 'mfbfw[padding]' parameter, allowing arbitrary JavaScript execution.

Description

The FancyBox for WordPress plugin before 3.0.3 for WordPress does not properly restrict access, which allows remote attackers to conduct cross-site scripting (XSS) attacks via an mfbfw[*] parameter in an update action to wp-admin/admin-post.php, as demonstrated by the mfbfw[padding] parameter and exploited in the wild in February 2015.

Exploits (1)

exploitdb WORKING POC VERIFIED
by NULLpOint7r · textwebappsphp
https://www.exploit-db.com/exploits/36087

This exploit demonstrates a stored XSS vulnerability in the WordPress plugin Fancybox-for-WordPress (version 3.0.2). The vulnerability arises due to insufficient sanitization of user input in the 'mfbfw[padding]' parameter, allowing arbitrary JavaScript execution.

Classification
Working Poc 95%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Fancybox-for-WordPress 3.0.2
Auth required
Prerequisites: Access to a WordPress admin account · Plugin installed and activated
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/72506
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2015/02/05/10
Issue Tracking x_refsource_confirm
https://plugins.trac.wordpress.org/changeset/1082625/
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/36087
Broken Link vdb-entry x_refsource_osvdb
http://osvdb.org/show/osvdb/118543

Scores

EPSS 0.0641
EPSS Percentile 92.8%

Details

VulnCheck KEV 2015-02-17
InTheWild.io 2021-07-20
CWE
CWE-79
Status published
Products (1)
colorlib/fancybox < 3.0.2
Published Feb 17, 2015
Tracked Since Feb 18, 2026