Medium severity6.1NVD Advisory· Published Sep 11, 2017· Updated May 13, 2026
CVE-2015-8353
CVE-2015-8353
Description
Cross-site scripting (XSS) vulnerability in the Role Scoper plugin before 1.3.67 for WordPress allows remote attackers to inject arbitrary web script or HTML via the object_name parameter in a rs-object_role_edit page to wp-admin/admin.php.
Affected products
1- cpe:2.3:a:role_scoper_project:role_scoper:*:*:*:*:*:wordpress:*:*Range: <=1.3.66
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- packetstormsecurity.com/files/134600/WordPress-Role-Scoper-1.3.66-Cross-Site-Scripting.htmlnvdExploitThird Party AdvisoryVDB Entry
- wordpress.org/plugins/role-scoper/nvdRelease NotesThird Party Advisory
- wpvulndb.com/vulnerabilities/8347nvdThird Party Advisory
- www.htbridge.com/advisory/HTB23276nvdThird Party Advisory
- www.securityfocus.com/archive/1/537019/100/0/threadednvd
News mentions
0No linked articles in our index yet.