CVE-2015-4063

NUCLEI

NewStatPress < 0.9.8 - Authenticated Cross-Site Scripting via where1 Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2015-4063. PoCs published by Adrián M. F.. A Nuclei detection template is also available.

AI-analyzed exploit summary The code describes two vulnerabilities in the WordPress plugin 'NewStatPress' version 0.9.8: an authenticated SQL injection (CVE-2015-4062) and an authenticated XSS (CVE-2015-4063). It includes proof-of-concept URLs and SQLMap output for the SQLi vulnerability.

Description

Cross-site scripting (XSS) vulnerability in includes/nsp_search.php in the NewStatPress plugin before 0.9.9 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the where1 parameter in the nsp_search page to wp-admin/admin.php.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Adrián M. F. · textwebappsphp
https://www.exploit-db.com/exploits/37107

The code describes two vulnerabilities in the WordPress plugin 'NewStatPress' version 0.9.8: an authenticated SQL injection (CVE-2015-4062) and an authenticated XSS (CVE-2015-4063). It includes proof-of-concept URLs and SQLMap output for the SQLi vulnerability.

Classification
Writeup 100%
Attack Type
Sqli | Xss
Complexity
Trivial
Reliability
Reliable
Target: WordPress plugin NewStatPress 0.9.8
Auth required
Prerequisites: Authenticated access to WordPress admin panel
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Nuclei Templates (1)

NewStatPress <0.9.9 - Cross-Site Scripting
LOWVERIFIEDby r3Y3r53

References (4)

Core 4
Core References
Patch, Vendor Advisory x_refsource_confirm
https://wordpress.org/plugins/newstatpress/changelog/
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/74773
Exploit exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/37107/

Scores

EPSS 0.0106
EPSS Percentile 78.1%

Details

CWE
CWE-79
Status published
Products (1)
newstatpress_project/newstatpress < 0.9.8
Published May 27, 2015
Tracked Since Feb 18, 2026