MainWP Dashboard - WordPress <3.1.2 - XSS
Title source: llmExploitation Summary
CVE-2016-15041 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including flame-11. A Nuclei detection template is also available.
AI-analyzed exploit summary This repository provides a functional exploit PoC for CVE-2016-15041, an unauthenticated stored XSS vulnerability in MainWP Dashboard WordPress plugin <= 3.1.2. It includes a Dockerized lab environment and a script to demonstrate the XSS injection via the `mwp_setup_purchase_username` parameter.
Description
The MainWP Dashboard – The Private WordPress Manager for Multiple Website Maintenance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mwp_setup_purchase_username’ parameter in versions up to, and including, 3.1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Exploits (1)
This repository provides a functional exploit PoC for CVE-2016-15041, an unauthenticated stored XSS vulnerability in MainWP Dashboard WordPress plugin <= 3.1.2. It includes a Dockerized lab environment and a script to demonstrate the XSS injection via the `mwp_setup_purchase_username` parameter.
Nuclei Templates (1)
/wp-content/plugins/mainwp/
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N