CVE-2016-1000127Patch(ajax-random-post_project / ajax-random-post)

LOWCVSS 6.1 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch ajax-random-post_project ajax-random-post systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Reflected XSS in wordpress plugin ajax-random-post v2.00

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ajax-random-post

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Products
ajax-random-post

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-05: 1PoC Mentioned / Linked · 2026-02-05: 1Patch / Workaround · 2026-02-05: 1Technical Details · 2026-02-05: 102-05
Signal classification1 categories
Patch
1100.0%
Full discourse1 post
  • Ostorlab@OstorlabSec
    Patch

    🚨 CVE-2016-1000127 : WORDPRESS PLUGIN XSS ALERT 🚨 A reflected cross-site scripting (XSS) vulnerability has been disclosed in the Ajax Random Post WordPress plugin. The flaw allows unauthenticated attackers to inject arbitrary JavaScript via crafted URLs, which executes when a logged-in administrator interacts with the malicious link. - Risk Severity: - Medium (CVSS 6.1, public proof-of-concept available, fix unavailable) Impact: - JavaScript execution in WordPress admin context - Session hijacking via theft of `wordpress_logged_in_*` cookies and nonces - Full administrative site takeover - Unauthorized plugin installation and configuration changes - Website defacement and persistent compromise - Pivoting attacks against site visitors Root Cause: - CWE-79 (Improper Neutralization of Input During Web Page Generation). The plugin’s AJAX handler fails to sanitize the `random_post_id` parameter before reflecting it in the response, enabling reflected XSS through the `admin-ajax.php` endpoint. Attackers can: - Craft malicious URLs targeting `admin-ajax.php?action=random_post` - Lure authenticated administrators via phishing or social engineering - Execute arbitrary JavaScript in the WordPress admin session - Steal session cookies, nonces, and credentials - Escalate privileges and persist via plugin or theme abuse Are You Affected? - Vulnerable: Ajax Random Post plugin v2.00 - Scope: Internet-facing WordPress sites with the plugin installed - Exposure amplified on sites without CSP headers or WAF protections - Status: Plugin permanently removed from Wordpress repository Immediate Action Required: - Remove: Completely delete the `ajax-random-post/` plugin directory — no patched version exists - Mitigation: If removal is delayed, deploy CSP headers and WAF rules blocking suspicious `random_post_id` patterns - Audit: Review web server and WordPress logs for malicious AJAX requests and anomalous admin activity Abandoned plugins remain a silent takeover vector. Remove legacy WordPress components immediately. 🛡️ #ostorlabCVE

    Post summary

    The post discloses a reflected XSS flaw in the Ajax Random Post WordPress plugin, details its impact and severity, and emphasizes removal of the unpatched plugin as the only mitigation.

    0000058
    582 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appajax-random-post_projectajax-random-post-wordpress-

Explore more