3.5
CVSSv2

CVE-2015-6805

Published: 02/09/2015 Updated: 22/12/2016
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
VMScore: 355
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the MDC Private Message plugin 1.0.0 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the message field in a private message.

Vulnerable Product Search on Vulmon Subscribe to Product

medhabidotcom mdc private message 1.0.0

Exploits

# Exploit Title: WordPress MDC Private Message Persistent XSS # Date: 8/20/15 # Exploit Author: Chris Kellum # Vendor Homepage: medhabicom/ # wordpressorg/plugins/mdc-private-message/ # Version: 100 ===================== Vulnerability Details ===================== The 'message' field doesn't sanitize input, allowing a less pr ...