CVE-2015-5622
LOW 3.5EPSS 4.7%
Cross-site scripting (XSS) vulnerability in WordPress before 4.2.3 allows remote authenticated users to inject arbitrary web script or HTML by leveraging the Author or Contributor role to place a crafted shortcode inside an HTML element, related to wp-includes/kses.php and wp-includes/shortcodes.php.
- CVSS v2.0
- 3.5 LOW
AV:N/AC:M/Au:S/C:N/I:P/A:N - EPSS
- 4.74% chance of exploitation in the next 30 days, 91th percentile
- Nuclei
- low
- Published
- 2015-08-03
- Updated
- 2024-08-06
Proof-of-concept exploits (2)
- ahmedj98/Pentesting-Unit-70★ · 2021-11-03
- lihaojin/WordPress-Pentesting0★ · 2018-04-18