Record summary

CVE-2015-7377 has a selected CVSS score of 4.3; EIP currently links 1 curated repository PoC and 1 Nuclei template.

Description

Cross-site scripting (XSS) vulnerability in pie-register/pie-register.php in the Pie Register plugin before 2.0.19 for WordPress allows remote attackers to inject arbitrary web script or HTML via the invitaion_code parameter in a pie-register page to the default URI.

Description source: CVE List

Exploitation context

Available material

Curated repository PoCs
1
Nuclei templates
1

Proofs of concept

1

Curated repository PoCs

GitHubCVE-2015-7377Curated repository PoCby yubsyStars: 112Not analyzed1 file

Python · 1.5 KiB

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress Pie-Register <2.0.19 - Cross-Site ScriptingCVSS 4.3

WordPress Pie Register before 2.0.19 contains a reflected cross-site scripting vulnerability in pie-register/pie-register.php which allows remote attackers to inject arbitrary web script or HTML via the invitaion_code parameter in a pie-register page to the default URL.

Impact

Successful exploitation of this vulnerability could lead to the execution of arbitrary script code in the context of the affected website, potentially allowing an attacker to steal sensitive information or perform unauthorized actions.

Remediation

Update to the latest version of the WordPress Pie-Register plugin (2.0.19 or higher) to mitigate this vulnerability.

WeaknessesCWE-79
Authorsdaffainfo
Template tagscvecve2015wordpresswp-pluginxsspacketstormgenetechsolutionsvuln
CVSS vector: CVSS:2.0/AV:N/AC:M/Au:N/C:N/I:P/A:N
CPE: cpe:2.3:a:genetechsolutions:pie_register:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

5