CVE-2015-4127
NUCLEIChurch Admin < 0.800 - Cross-Site Scripting via Address Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2015-4127. PoCs published by woodspeed. A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in the WordPress church_admin plugin version 0.800. The address field in the registration form is not properly sanitized, allowing arbitrary JavaScript execution when the Directory page is visited.
Description
Cross-site scripting (XSS) vulnerability in the church_admin plugin before 0.810 for WordPress allows remote attackers to inject arbitrary web script or HTML via the address parameter, as demonstrated by a request to index.php/2015/05/21/church_admin-registration-form/.
Exploits (1)
This exploit demonstrates a stored XSS vulnerability in the WordPress church_admin plugin version 0.800. The address field in the registration form is not properly sanitized, allowing arbitrary JavaScript execution when the Directory page is visited.