Medium severity4.8NVD Advisory· Published Sep 12, 2017· Updated May 13, 2026
CVE-2015-9230
CVE-2015-9230
Description
In the admin/db-backup-security/db-backup-security.php page in the BulletProof Security plugin before .52.5 for WordPress, XSS is possible for remote authenticated administrators via the DBTablePrefix parameter.
Affected products
1- cpe:2.3:a:ait-pro:bulletproof_security:.52.4:*:*:*:*:wordpress:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- www.openwall.com/lists/oss-security/2015/10/27/3nvdExploitMailing ListThird Party Advisory
- cxsecurity.com/issue/WLB-2016010011nvdExploitThird Party Advisory
- cybersecurityworks.com/zerodays/cve-2015-9230-bulletproof.htmlnvdExploitThird Party Advisory
- github.com/cybersecurityworks/Disclosed/issues/3nvdExploitThird Party Advisory
- packetstormsecurity.com/files/135125/BulletProof-Security-.52.4-Cross-Site-Scripting.htmlnvdExploitThird Party AdvisoryVDB Entry
- forum.ait-pro.com/forums/topic/bps-changelog/nvdThird Party Advisory
- wpvulndb.com/vulnerabilities/8224nvdThird Party Advisory
News mentions
0No linked articles in our index yet.