CVE-2015-4039
Last modified
CVE-2015-4039 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. Multiple cross-site scripting (XSS) vulnerabilities in the WP Membership plugin 1.2.3 for WordPress allow remote authenticated users to inject arbitrary web script or HTML via unspecified (1) profile fields or (2) new post content. NOTE: CVE-2015-4038 can be used to bypass the administrator confirmation step for vector 2.. EPSS estimates a 2.79% chance of exploitation in the next 30 days.
Description
Multiple cross-site scripting (XSS) vulnerabilities in the WP Membership plugin 1.2.3 for WordPress allow remote authenticated users to inject arbitrary web script or HTML via unspecified (1) profile fields or (2) new post content. NOTE: CVE-2015-4038 can be used to bypass the administrator confirmation step for vector 2.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| E-Plugins | Wp Membership | 1.2.3 |
References
- http://packetstormsecurity.com/files/132011/WordPress-WP-Membership-1.2.3-Cross-Site-Scripting.htmlExploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/archive/1/535586/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/74766Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/37074/Exploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/132011/WordPress-WP-Membership-1.2.3-Cross-Site-Scripting.htmlExploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/archive/1/535586/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/74766Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/37074/Exploit, Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-4039?
How severe is CVE-2015-4039?
How do I fix CVE-2015-4039?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2015
- CVE-2015-4033Samsung SBeam allows remote attackers to read arbitrary imag…
- CVE-2015-4034The createFromParcel method in the com.absolute.android.pers…
- CVE-2015-4035scripts/xzgrep.in in xzgrep 5.2.x before 5.2.0, before 5.0.0…
- CVE-2015-4036Array index error in the tcm_vhost_make_tpg function in driv…
- CVE-2015-4037The slirp_smb function in net/slirp.c in QEMU 2.3.0 and earl…
- CVE-2015-4038The WP Membership plugin 1.2.3 for WordPress allows remote a…
- CVE-2015-4040Directory traversal vulnerability in the configuration utili…
- CVE-2015-4041The keycompare_mb function in sort.c in sort in GNU Coreutil…7.8
- CVE-2015-4042Integer overflow in the keycompare_mb function in sort.c in …9.8
- CVE-2015-4043SQL injection vulnerability in ConnX ESP HR Management 4.4.0…
- CVE-2015-4045The sudoers file in the asset discovery scanner in AlienVaul…
- CVE-2015-4046The asset discovery scanner in AlienVault OSSIM before 5.0.1…
Are you affected by CVE-2015-4039?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
