header-logo
Suggest Exploit
vendor:
Wordpress White-Label Framework
by:
Outlasted
7,5
CVSS
HIGH
Cross-Site Scripting (XSS)
79
CWE
Product Name: Wordpress White-Label Framework
Affected Version From: 2.0.6
Affected Version To: 2.0.6
Patch Exists: Yes
Related CWE: N/A
CPE: a:wordpress:wordpress
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2015

WordPress White-Label Framework XSS

A Cross-Site Scripting (XSS) vulnerability exists in Wordpress White-Label Framework version 2.0.6. An attacker can exploit this vulnerability by entering their XSS payload in all forms.

Mitigation:

Upgrade to the latest version of Wordpress White-Label Framework.
Source

Exploit-DB raw data:

# Exploit Title: Wordpress White-Label Framework XSS
# Google Dork: inurl:/wp-content/themes/whitelabel-framework/inc/form-sharebymail_iframe.php
# Date: 7 September 2015
# Exploit Author: Outlasted
# Software Link: wordpress.com / http://whitelabelframework.com/
# Version: 2.0.6
#Greetz to: TeaMp0isoN
=====================================================
Vulnerable url: /wp-content/themes/whitelabel-framework/inc/form-sharebymail_iframe.php


=====================================================
How to exploit?
----------------------------------------------------------------------------------------------------------

Enter your XSS payload in all forms and watch the magic.