.. / CVE-2015-7377

Exploit for WordPress Pie-Register <2.0.19 - Cross-Site Scripting (CVE-2015-7377)

Description:

WordPress Pie Register before 2.0.19 contains a reflected cross-site scripting vulnerability in pie-register/pie-register.php which allows remote attackers to inject arbitrary web script or HTML via the invitaion_code parameter in a pie-register page to the default URL.

Nuclei Template

View the template here CVE-2015-7377.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2015/CVE-2015-7377.yaml
Copy

References:

https://wpvulndb.com/vulnerabilities/8212
https://nvd.nist.gov/vuln/detail/CVE-2015-7377
https://packetstormsecurity.com/files/133928/WordPress-Pie-Register-2.0.18-Cross-Site-Scripting.html
https://github.com/GTSolutions/Pie-Register/blob/2.0.19/readme.txt
http://packetstormsecurity.com/files/133928/WordPress-Pie-Register-2.0.18-Cross-Site-Scripting.html