93804vdb entry
http://www.securityfocus.com/bid/93804 CVE-2016-1000141
MEDIUMNuclei
WordPress Page Layout builder v1.9.3 - Cross-Site Scripting
Record summary
CVE-2016-1000141 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
Reflected XSS in wordpress plugin page-layout-builder v1.9.3
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryMEDIUMWordPress Page Layout builder v1.9.3 - Cross-Site ScriptingCVSS 6.1
WordPress plugin Page-layout-builder v1.9.3 contains a cross-site scripting vulnerability.
Impact
Successful exploitation of this vulnerability could allow an attacker to inject malicious scripts into web pages viewed by users, leading to potential data theft, session hijacking, or defacement of the affected website.
Remediation
Upgrade to version 2.0 or higher.
WeaknessesCWE-79
Authorsdaffainfo
Template tagscvecve2016wordpressxsswp-pluginpage-layout-builder_projectvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:page-layout-builder_project:page-layout-builder:*:*:*:*:*:wordpress:*:*
Google: inurl:"/wp-content/plugins/page-layout-builder"
http://www.vapidlabs.com/wp/wp_advisory.php?v=358 https://nvd.nist.gov/vuln/detail/CVE-2016-1000141 https://wordpress.org/plugins/page-layout-builder https://github.com/ARPSyndicate/kenzer-templates
Source: ProjectDiscovery
References
4vapidlabs.com
http://www.vapidlabs.com/wp/wp_advisory.php?v=358 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2016-1000141 wordpress.org
https://wordpress.org/plugins/page-layout-builder