Record summary

CVE-2016-1000127 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

Reflected XSS in wordpress plugin ajax-random-post v2.00

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress AJAX Random Post <=2.00 - Cross-Site ScriptingCVSS 6.1

WordPress AJAX Random Post 2.00 is vulnerable to reflected cross-site scripting.

Impact

This vulnerability allows an attacker to execute arbitrary JavaScript code in the context of the victim's browser, potentially leading to session hijacking, defacement, or theft of sensitive information.

Remediation

Update to the latest version of the WordPress AJAX Random Post plugin (2.00 or higher) to fix this issue.

WeaknessesCWE-79
Authorsdaffainfo
Template tagscve2016cvewordpressxsswp-pluginajax-random-post_projectvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:ajax-random-post_project:ajax-random-post:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

4