.. / CVE-2015-9414

Exploit for WordPress Symposium <=15.8.1 - Cross-Site Scripting (CVE-2015-9414)

Description:

WordPress Symposium through 15.8.1 contains a reflected cross-site scripting vulnerability via the wp-content/plugins/wp-symposium/get_album_item.php?size parameter which allows an attacker to steal cookie-based authentication credentials and launch other attacks.

Nuclei Template

View the template here CVE-2015-9414.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2015/CVE-2015-9414.yaml
Copy

References:

https://nvd.nist.gov/vuln/detail/CVE-2015-9414
https://wpvulndb.com/vulnerabilities/8175
https://wordpress.org/plugins/wp-symposium/#developers
https://github.com/ARPSyndicate/kenzer-templates
https://wpscan.com/vulnerability/2ac2d43f-bf3f-4831-9585-5c5484051095