CVE-2015-2807
NUCLEINavis DocumentCloud < 0.1 - Cross-Site Scripting via wpbase Parameter
Title source: llmExploitation Summary
CVE-2015-2807 has a Nuclei detection template available — see the Nuclei card below for the Shodan/FOFA recon queries.
Description
Cross-site scripting (XSS) vulnerability in js/window.php in the Navis DocumentCloud plugin before 0.1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the wpbase parameter.
Nuclei Templates (1)
Navis DocumentCloud <0.1.1 - Cross-Site Scripting
MEDIUMby daffainfo
References (5)
Core 5
Core References
Exploit x_refsource_misc
http://packetstormsecurity.com/files/133350/WordPress-Navis-DocumentCloud-0.1-Cross-Site-Scripting.html
Patch x_refsource_confirm
https://wordpress.org/plugins/navis-documentcloud/changelog/
Exploit mailing-list
x_refsource_fulldisc
http://seclists.org/fulldisclosure/2015/Aug/78
Exploit x_refsource_misc
https://security.dxw.com/advisories/publicly-exploitable-xss-in-wordpress-plugin-navis-documentcloud/
Third Party Advisory x_refsource_misc
https://wpvulndb.com/vulnerabilities/8164
Scores
EPSS
0.0689
EPSS Percentile
91.6%
Details
CWE
CWE-79
Status
published
Products (1)
documentcloud/navis_documentcloud
< 0.1
Published
Sep 01, 2015
Tracked Since
Feb 18, 2026