CVE-2016-15041

HIGH EXPLOITED NUCLEI LAB

MainWP Dashboard - WordPress <3.1.2 - XSS

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2016-15041 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including flame-11. A Nuclei detection template is also available.

AI-analyzed exploit summary This repository provides a functional exploit PoC for CVE-2016-15041, an unauthenticated stored XSS vulnerability in MainWP Dashboard WordPress plugin <= 3.1.2. It includes a Dockerized lab environment and a script to demonstrate the XSS injection via the `mwp_setup_purchase_username` parameter.

Description

The MainWP Dashboard – The Private WordPress Manager for Multiple Website Maintenance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mwp_setup_purchase_username’ parameter in versions up to, and including, 3.1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Exploits (1)

nomisec WORKING POC
by flame-11 · client-side
https://github.com/flame-11/CVE-2016-15041-mainwp-dashboard

This repository provides a functional exploit PoC for CVE-2016-15041, an unauthenticated stored XSS vulnerability in MainWP Dashboard WordPress plugin <= 3.1.2. It includes a Dockerized lab environment and a script to demonstrate the XSS injection via the `mwp_setup_purchase_username` parameter.

Classification
Working Poc 95%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: MainWP Dashboard WordPress plugin <= 3.1.2
No auth needed
Prerequisites: Docker · WordPress environment with MainWP Dashboard plugin <= 3.1.2 installed
devstral-2 · analyzed Feb 19, 2026 Full analysis →

Nuclei Templates (1)

MainWP Dashboard <= 3.1.2 - Stored Cross-Site Scripting
HIGHVERIFIEDby flame
FOFA: /wp-content/plugins/mainwp/

Scores

CVSS v3 7.2
EPSS 0.0123
EPSS Percentile 64.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Lab Environment

COMMUNITY
Community Lab
docker pull wordpress:6.2-php8.1-apache

Details

VulnCheck KEV 2024-10-15
CWE
CWE-79
Status published
Products (2)
mainwp/MainWP Dashboard: Self-hosted WordPress Management for Agencies < 3.1.3
mainwp/mainwp_dashboard < 3.1.2
Published Oct 16, 2024
Tracked Since Feb 18, 2026