Multiple cross-site scripting (XSS) vulnerabilities in the WP Membership plugin 1.2.3 for WordPress allow remote authenticated users to inject arbitrary web script or HTML via unspecified (1) profile fields or (2) new post content. NOTE: CVE-2015-4038 can be used to bypass the administrator confirmation step for vector 2.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2020-01-06T18:40:57

Updated: 2024-08-06T06:04:02.389Z

Reserved: 2015-05-19T00:00:00

Link: CVE-2015-4039

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2020-01-06T19:15:11.423

Modified: 2020-01-13T19:00:49.747

Link: CVE-2015-4039

cve-icon Redhat

No data.