4.3
CVSSv2

CVE-2015-3647

Published: 21/05/2015 Updated: 09/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in wppa-ajax-front.php in the WP Photo Album Plus (aka WPPA) plugin prior to 6.1.3 for WordPress allow remote malicious users to inject arbitrary web script or HTML via the (1) comemail or (2) comname parameter in a wppa do-comment action.

Vulnerable Product Search on Vulmon Subscribe to Product

wppa.opajaap wp-photo-album-plus

Exploits

WordPress WP Photo Album Plus plugin version 612 suffers from a cross site scripting vulnerability ...