CVE-2015-4127: XSS
Cross-site scripting (XSS) vulnerability in the churchadmin plugin before 0.810 for WordPress allows remote attackers to inject arbitrary web script or HTML via the address parameter, as demonstrated by a request to index.php/2015/05/21/churchadmin-registration-form/.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-4127?
CVE-2015-4127 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2015-4127?
To fix CVE-2015-4127, update the church_admin plugin to version 0.810 or later.
What type of vulnerability is CVE-2015-4127?
CVE-2015-4127 is a cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary web scripts or HTML.
Who is affected by CVE-2015-4127?
CVE-2015-4127 affects users of the church_admin plugin for WordPress versions prior to 0.810.
What could attackers do with CVE-2015-4127?
Attackers could exploit CVE-2015-4127 to execute malicious scripts in the context of a user's browser session.