.. / CVE-2019-15858

Exploit for WordPress Woody Ad Snippets <2.2.5 - Cross-Site Scripting/Remote Code Execution (CVE-2019-15858)

Description:

WordPress Woody Ad Snippets prior to 2.2.5 is susceptible to cross-site scripting and remote code execution via admin/includes/class.import.snippet.php, which allows unauthenticated options import as demonstrated by storing a cross-site scripting payload for remote code execution.

Nuclei Template

View the template here CVE-2019-15858.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2019/CVE-2019-15858.yaml
Copy

References:

https://wpvulndb.com/vulnerabilities/9490
https://nvd.nist.gov/vuln/detail/CVE-2019-15858
https://github.com/ARPSyndicate/kenzer-templates
https://blog.nintechnet.com/multiple-vulnerabilities-in-wordpress-woody-ad-snippets-plugin-lead-to-remote-code-execution/
https://github.com/GeneralEG/CVE-2019-15858