packetstormsecurity.com
http://packetstormsecurity.com/files/133371/WordPress-sourceAFRICA-0.1.3-Cross-Site-Scripting.html CVE-2015-6920
Nuclei
WordPress sourceAFRICA <=0.1.3 - Cross-Site Scripting
Record summary
CVE-2015-6920 has a selected CVSS score of 4.3; EIP currently links 1 Nuclei template.
Description
Cross-site scripting (XSS) vulnerability in js/window.php in the sourceAFRICA plugin 0.1.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the wpbase parameter.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryMEDIUMWordPress sourceAFRICA <=0.1.3 - Cross-Site ScriptingCVSS 4.3
WordPress sourceAFRICA plugin version 0.1.3 contains a cross-site scripting vulnerability.
Impact
Attackers can execute malicious scripts in the victim's browser, potentially stealing cookies or session tokens.
Remediation
Update to the latest version of the plugin where the vulnerability is fixed.
WeaknessesCWE-79
Authorsdaffainfo
Template tagscve2015cvewp-pluginxsspacketstormwordpresssourceafrica_projectvuln
CVSS vector: CVSS:2.0/AV:N/AC:M/Au:N/C:N/I:P/A:N
CPE: cpe:2.3:a:sourceafrica_project:sourceafrica:0.1.3:*:*:*:*:wordpress:*:*
http://packetstormsecurity.com/files/133371/WordPress-sourceAFRICA-0.1.3-Cross-Site-Scripting.html https://wpvulndb.com/vulnerabilities/8169 https://nvd.nist.gov/vuln/detail/CVE-2015-6920 https://github.com/ARPSyndicate/kenzer-templates
Source: ProjectDiscovery
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2015-6920 wpvulndb.com
https://wpvulndb.com/vulnerabilities/8169