CVE-2015-5532
Paid Memberships Pro < 1.8.4.3 - Multiple Cross-Site Scripting
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
Multiple cross-site scripting (XSS) vulnerabilities in the Paid Memberships Pro (PMPro) plugin before 1.8.4.3 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) s parameter to membershiplevels.php, (2) memberslist.php, or (3) orders.php in adminpages/ or the (4) edit parameter to adminpages/membershiplevels.php.
Múltiples vulnerabilidades Cross-Site Scripting (XSS) en el plugin Paid Memberships Pro (PMPro) plugin en versiones anteriores a la 1.8.4.3 para WordPress permite que atacantes remotos inyecten scripts web o HTML arbitrarios mediante (1) el parámetro s en membershiplevels.php, (2) memberslist.php o (3) orders.php en adminpages/ o (4) el parámetro edit en adminpages/membershiplevels.php.
WordPress Paid Memberships Pro plugin version 1.8.4.2 suffers from a cross site scripting vulnerability.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2015-07-16 CVE Reserved
- 2015-07-22 CVE Published
- 2024-01-27 EPSS Updated
- 2024-08-06 CVE Updated
- 2024-08-06 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
http://www.paidmembershipspro.com/2015/07/pmpro-updates-1-8-4-3-and-1-8-4-4 | Release Notes | |
https://wordpress.org/plugins/paid-memberships-pro/#developers | Release Notes | |
https://wpvulndb.com/vulnerabilities/8109 | Third Party Advisory | |
https://www.htbridge.com/advisory/HTB23264 | Broken Link |
URL | Date | SRC |
---|---|---|
https://github.com/strangerstudios/paid-memberships-pro/commit/add03e3ed90e9163e5a46e20e6c371a87ff5a677 | 2021-04-06 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Strangerstudios Search vendor "Strangerstudios" | Paid Memberships Pro Search vendor "Strangerstudios" for product "Paid Memberships Pro" | < 1.8.4.3 Search vendor "Strangerstudios" for product "Paid Memberships Pro" and version " < 1.8.4.3" | wordpress |
Affected
|