3.5
CVSSv2

CVE-2015-6535

Published: 31/08/2015 Updated: 09/10/2018
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in includes/options-profiles.php in the YouTube Embed plugin prior to 3.3.3 for WordPress allows remote administrators to inject arbitrary web script or HTML via the Profile name field (youtube_embed_name parameter).

Vulnerable Product Search on Vulmon Subscribe to Product

youtube embed project youtube embed

Exploits

Details================Software: YouTube EmbedVersion: 332Homepage: wordpressorg/plugins/youtube-embed/CVE ID: CVE-2015-6535 (Pending)CWE ID: CWE-79CVSS: 55 (Medium; AV:N/AC:L/Au:S/C:P/I:P/A:N)Description================A stored XSS vulnerability in YouTube Embed 332 (and possibly earlier versions) allows admin users to compromise oth ...

Github Repositories

CodePath University's Web Security - Week 7: WordPress Pentesting (Spring 2018)

CodePath University's Web Security Project 7 - WordPress Pentesting Time spent: 5 hours spent in total Objective: Find, analyze, recreate, and document five vulnerabilities affecting an old version of WordPress Pentesting Report (Required) 422 - Authenticated Stored Cross-Site Scripting (XSS) Summary: A stored XSS vulnerability in WordPress allows an user with the

wordpress pentesting vulnerabilities affecting old version

WordPress Pentesting Time spent: 5 hours spent in total Objective: Find, analyze, recreate, and document five vulnerabilities affecting an old version of WordPress Pentesting Report 422 - Authenticated Stored Cross-Site Scripting (XSS) Vulnerability types: 42~ Tested in version: 42 Fixed in version: 423 GIF Walkthrough:

wordpress pentesting vulnerabilities affecting old version

WordPress Pentesting Time spent: 5 hours spent in total Objective: Find, analyze, recreate, and document five vulnerabilities affecting an old version of WordPress Pentesting Report 422 - Authenticated Stored Cross-Site Scripting (XSS) Vulnerability types: 42~ Tested in version: 42 Fixed in version: 423 GIF Walkthrough: