.. / CVE-2020-36510

Exploit for WordPress 15Zine <3.3.0 - Cross-Site Scripting (CVE-2020-36510)

Description:

WordPress 15Zine before 3.3.0 is vulnerable to reflected cross-site scripting because the theme does not sanitize the cbi parameter before including it in the HTTP response via the cb_s_a AJAX action.

Nuclei Template

View the template here CVE-2020-36510.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2020/CVE-2020-36510.yaml
Copy

References:

https://nvd.nist.gov/vuln/detail/CVE-2020-36510
https://github.com/ARPSyndicate/kenzer-templates
https://wpscan.com/vulnerability/d1dbc6d7-7488-40c2-bc38-0674ea5b3c95