CVE-2020-15038
MEDIUMSeedProd Coming Soon Page < 5.1.1 - Stored Cross-Site Scripting
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-15038. PoCs published by Jinson Varghese Behanan.
AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in the WordPress plugin 'Coming Soon Page, Under Construction & Maintenance Mode by SeedProd' version 5.1.1 and below. The PoC shows how an attacker can inject malicious JavaScript into the 'headline' field, which executes when the page is displayed.
Description
The SeedProd coming-soon plugin before 5.1.1 for WordPress allows XSS.
Exploits (1)
This exploit demonstrates a stored XSS vulnerability in the WordPress plugin 'Coming Soon Page, Under Construction & Maintenance Mode by SeedProd' version 5.1.1 and below. The PoC shows how an attacker can inject malicious JavaScript into the 'headline' field, which executes when the page is displayed.
References (5)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N