Record summary

CVE-2015-9414 has a selected CVSS score of 6.1 (medium); EIP currently links 1 curated repository PoC and 1 Nuclei template.

Description

The wp-symposium plugin through 15.8.1 for WordPress has XSS via the wp-content/plugins/wp-symposium/get_album_item.php?size parameter.

Description source: CVE List

Exploitation context

Available material

Curated repository PoCs
1
Nuclei templates
1

Proofs of concept

1

Curated repository PoCs

GitHubCVE-2015-9414Curated repository PoCby yubsyStars: 112Not analyzed1 file

Python · 361 B

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress Symposium <=15.8.1 - Cross-Site ScriptingCVSS 6.1

WordPress Symposium through 15.8.1 contains a reflected cross-site scripting vulnerability via the wp-content/plugins/wp-symposium/get_album_item.php?size parameter which allows an attacker to steal cookie-based authentication credentials and launch other attacks.

Impact

Successful exploitation of this vulnerability could allow an attacker to inject malicious scripts into web pages viewed by users, leading to potential data theft or unauthorized actions.

Remediation

Update to the latest version of the WordPress Symposium plugin (>=15.8.2) which includes a fix for this vulnerability.

WeaknessesCWE-79
Authorsdaffainfo
Template tagscve2015cvexsswpscanwordpresswp-pluginwpsymposiumprovuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:wpsymposiumpro:wp-symposium:*:*:*:*:*:wordpress:*:*
Google: inurl:"/wp-content/plugins/wp-symposium"

Source: ProjectDiscovery

References

3