4.3
CVSSv2

CVE-2015-4127

Published: 28/05/2015 Updated: 31/12/2016
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the church_admin plugin prior to 0.810 for WordPress allows remote malicious users to inject arbitrary web script or HTML via the address parameter, as demonstrated by a request to index.php/2015/05/21/church_admin-registration-form/.

Vulnerable Product Search on Vulmon Subscribe to Product

church admin project church admin

Exploits

# Exploit Title: Wordpress church_admin Stored XSS # Date: 21-04-2015 # Exploit Author: woodspeed # Vendor Homepage: wordpressorg/plugins/church-admin/ # Version: 0800 # OSVDB ID : wwwosvdborg/show/osvdb/121304 # WPVULNDB ID : wpvulndbcom/vulnerabilities/7999 # Category: webapps 1 Description On the registration form ...