Record summary

CVE-2015-4127 has a selected CVSS score of 4.3; EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

Cross-site scripting (XSS) vulnerability in the church_admin plugin before 0.810 for WordPress allows remote attackers to inject arbitrary web script or HTML via the address parameter, as demonstrated by a request to index.php/2015/05/21/church_admin-registration-form/.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Nuclei templates
1

Proofs of concept

1

Catalogued exploits

ExploitDBWordPress Plugin church_admin 0.800 - Persistent Cross-Site ScriptingExploitDB exploitby woodspeedNot analyzed1 file
ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress Church Admin <0.810 - Cross-Site ScriptingCVSS 4.3

WordPress Church Admin plugin before 0.810 allows remote attackers to inject arbitrary web script or HTML via the address parameter via index.php/2015/05/21/church_admin-registration-form/.

Impact

Allows attackers to inject malicious scripts into web pages viewed by users, leading to potential data theft or unauthorized actions.

Remediation

Update to the latest version of the WordPress Church Admin plugin (0.810 or higher) to mitigate this vulnerability.

WeaknessesCWE-79
Authorsdaffainfo
Template tagscve2015cvewp-pluginwpedbwpscanwordpressxsschurch_admin_projectvuln
CVSS vector: CVSS:2.0/AV:N/AC:M/Au:N/C:N/I:P/A:N
CPE: cpe:2.3:a:church_admin_project:church_admin:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

6