Cross-site scripting (XSS) vulnerability in the Wordfence Security plugin before 5.1.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the val parameter to whois.php.
- http://techdefencelabs.com/security-advisories.html
- https://github.com/20142995/nuclei-templates
- https://github.com/RJSOG/cve-scrapper