93895vdb entry
http://www.securityfocus.com/bid/93895 CVE-2016-1000127
MEDIUMNuclei
WordPress AJAX Random Post <=2.00 - Cross-Site Scripting
Record summary
CVE-2016-1000127 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
Reflected XSS in wordpress plugin ajax-random-post v2.00
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryMEDIUMWordPress AJAX Random Post <=2.00 - Cross-Site ScriptingCVSS 6.1
WordPress AJAX Random Post 2.00 is vulnerable to reflected cross-site scripting.
Impact
This vulnerability allows an attacker to execute arbitrary JavaScript code in the context of the victim's browser, potentially leading to session hijacking, defacement, or theft of sensitive information.
Remediation
Update to the latest version of the WordPress AJAX Random Post plugin (2.00 or higher) to fix this issue.
WeaknessesCWE-79
Authorsdaffainfo
Template tagscve2016cvewordpressxsswp-pluginajax-random-post_projectvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:ajax-random-post_project:ajax-random-post:*:*:*:*:*:wordpress:*:*
http://www.vapidlabs.com/wp/wp_advisory.php?v=494 https://wordpress.org/plugins/ajax-random-post https://nvd.nist.gov/vuln/detail/CVE-2016-1000127 https://github.com/ARPSyndicate/kenzer-templates
Source: ProjectDiscovery
References
4vapidlabs.com
http://www.vapidlabs.com/wp/wp_advisory.php?v=494 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2016-1000127 wordpress.org
https://wordpress.org/plugins/ajax-random-post