CVE-2015-4127
WordPress Plugin church_admin 0.800 - Persistent Cross-Site Scripting
Record summary
CVE-2015-4127 has a selected CVSS score of 4.3; EIP currently links 1 catalogued exploit and 1 Nuclei template.
Description
Cross-site scripting (XSS) vulnerability in the church_admin plugin before 0.810 for WordPress allows remote attackers to inject arbitrary web script or HTML via the address parameter, as demonstrated by a request to index.php/2015/05/21/church_admin-registration-form/.
Exploitation context
Proofs of concept
1Catalogued exploits
ExploitDBWordPress Plugin church_admin 0.800 - Persistent Cross-Site ScriptingExploitDB exploitby woodspeedNot analyzed1 file
Nuclei templates
1ProjectDiscoveryMEDIUMWordPress Church Admin <0.810 - Cross-Site ScriptingCVSS 4.3
WordPress Church Admin plugin before 0.810 allows remote attackers to inject arbitrary web script or HTML via the address parameter via index.php/2015/05/21/church_admin-registration-form/.
Impact
Allows attackers to inject malicious scripts into web pages viewed by users, leading to potential data theft or unauthorized actions.
Remediation
Update to the latest version of the WordPress Church Admin plugin (0.810 or higher) to mitigate this vulnerability.
Source: ProjectDiscovery