mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-06 02:31:38 +00:00
23 lines
986 B
Markdown
23 lines
986 B
Markdown
![]() |
### [CVE-2015-5732](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5732)
|
||
|

|
||
|

|
||
|

|
||
|
|
||
|
### Description
|
||
|
|
||
|
Cross-site scripting (XSS) vulnerability in the form function in the WP_Nav_Menu_Widget class in wp-includes/default-widgets.php in WordPress before 4.2.4 allows remote attackers to inject arbitrary web script or HTML via a widget title.
|
||
|
|
||
|
### POC
|
||
|
|
||
|
#### Reference
|
||
|
- https://wpvulndb.com/vulnerabilities/8131
|
||
|
|
||
|
#### Github
|
||
|
- https://github.com/ARPSyndicate/cvemon
|
||
|
- https://github.com/Afetter618/WordPress-PenTest
|
||
|
- https://github.com/CyberDefender369/Web-Security-WordPress-Pen-Testing
|
||
|
- https://github.com/CyberDefender369/WordPress-Pen-Testing
|
||
|
- https://github.com/SLyubar/codepath_Unit8
|
||
|
- https://github.com/jguerrero12/WordPress-Pentesting
|
||
|
|