CVE-2015-4039

MEDIUM

WP Membership 1.2.3 - Authenticated Cross-Site Scripting via Profile Fields or New Post Content

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2015-4039. PoCs published by Panagiotis Vagenas.

AI-analyzed exploit summary This writeup details multiple vulnerabilities in the WordPress WP Membership plugin, including privilege escalation, stored XSS, and unauthorized post publishing. It provides proof-of-concept steps but lacks executable exploit code.

Description

Multiple cross-site scripting (XSS) vulnerabilities in the WP Membership plugin 1.2.3 for WordPress allow remote authenticated users to inject arbitrary web script or HTML via unspecified (1) profile fields or (2) new post content. NOTE: CVE-2015-4038 can be used to bypass the administrator confirmation step for vector 2.

Exploits (1)

exploitdb WRITEUP
by Panagiotis Vagenas · textwebappsphp
https://www.exploit-db.com/exploits/37074

This writeup details multiple vulnerabilities in the WordPress WP Membership plugin, including privilege escalation, stored XSS, and unauthorized post publishing. It provides proof-of-concept steps but lacks executable exploit code.

Classification
Writeup 90%
Attack Type
Auth Bypass | Xss | Other
Complexity
Trivial
Reliability
Reliable
Target: WordPress WP Membership plugin 1.2.3
Auth required
Prerequisites: registered user account · access to plugin functionality
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Broken Link, Third Party Advisory, VDB Entry x_refsource_misc
http://www.securityfocus.com/archive/1/archive/1/535586/100/0/threaded
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
https://www.exploit-db.com/exploits/37074/
Third Party Advisory, VDB Entry x_refsource_misc
http://www.securityfocus.com/bid/74766

Scores

CVSS v3 5.4
EPSS 0.0279
EPSS Percentile 84.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
e-plugins/wp_membership 1.2.3
Published Jan 06, 2020
Tracked Since Feb 18, 2026