CVE-2015-4039

MEDIUM

E-plugins WP Membership - XSS

Title source: rule
STIX 2.1

Description

Multiple cross-site scripting (XSS) vulnerabilities in the WP Membership plugin 1.2.3 for WordPress allow remote authenticated users to inject arbitrary web script or HTML via unspecified (1) profile fields or (2) new post content. NOTE: CVE-2015-4038 can be used to bypass the administrator confirmation step for vector 2.

Exploits (1)

exploitdb WRITEUP
by Panagiotis Vagenas · textwebappsphp
https://www.exploit-db.com/exploits/37074

References (4)

Core 4
Core References
Broken Link, Third Party Advisory, VDB Entry x_refsource_misc
http://www.securityfocus.com/archive/1/archive/1/535586/100/0/threaded
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
https://www.exploit-db.com/exploits/37074/
Third Party Advisory, VDB Entry x_refsource_misc
http://www.securityfocus.com/bid/74766

Scores

CVSS v3 5.4
EPSS 0.0025
EPSS Percentile 48.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
e-plugins/wp_membership 1.2.3
Published Jan 06, 2020
Tracked Since Feb 18, 2026