CVE-2015-7377
WordPress Pie-Register <2.0.19 - Cross-Site Scripting
Record summary
CVE-2015-7377 has a selected CVSS score of 4.3; EIP currently links 1 curated repository PoC and 1 Nuclei template.
Description
Cross-site scripting (XSS) vulnerability in pie-register/pie-register.php in the Pie Register plugin before 2.0.19 for WordPress allows remote attackers to inject arbitrary web script or HTML via the invitaion_code parameter in a pie-register page to the default URI.
Exploitation context
Proofs of concept
1Curated repository PoCs
GitHubCVE-2015-7377Curated repository PoCby yubsyStars: 112Not analyzed1 file
Nuclei templates
1ProjectDiscoveryMEDIUMWordPress Pie-Register <2.0.19 - Cross-Site ScriptingCVSS 4.3
WordPress Pie Register before 2.0.19 contains a reflected cross-site scripting vulnerability in pie-register/pie-register.php which allows remote attackers to inject arbitrary web script or HTML via the invitaion_code parameter in a pie-register page to the default URL.
Impact
Successful exploitation of this vulnerability could lead to the execution of arbitrary script code in the context of the affected website, potentially allowing an attacker to steal sensitive information or perform unauthorized actions.
Remediation
Update to the latest version of the WordPress Pie-Register plugin (2.0.19 or higher) to mitigate this vulnerability.
Source: ProjectDiscovery