Record summary

CVE-2017-9288 has a selected CVSS score of 6.1 (medium); EIP currently links 2 curated repository PoCs and 1 Nuclei template.

Description

The Raygun4WP plugin 1.8.0 for WordPress is vulnerable to a reflected XSS in sendtesterror.php (backurl parameter).

Description source: CVE List

Exploitation context

Available material

Curated repository PoCs
2
Nuclei templates
1

Proofs of concept

2

Curated repository PoCs

GitHubCVE-2017-9288Curated repository PoCby yubsyStars: 112Not analyzed1 file

Python · 306 B

GitHub

PoC details
GitHubCVE-2017-9288Curated repository PoCby 0xd3vilStars: 127Not analyzed1 file

Python · 306 B

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress Raygun4WP <=1.8.0 - Cross-Site ScriptingCVSS 6.1

WordPress Raygun4WP 1.8.0 contains a reflected cross-site scripting vulnerability via sendtesterror.php.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary script code in the context of the affected website, potentially leading to session hijacking, defacement, or theft of sensitive information.

Remediation

Update to the latest version of the WordPress Raygun4WP plugin (1.8.0 or higher) to mitigate this vulnerability.

WeaknessesCWE-79
Authorsdaffainfo
Template tagscve2017cvewordpressxsswp-pluginraygunvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:raygun:raygun4wp:1.8.0:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

5