CVE-2015-3440

Exp

Cross-site scripting (XSS) vulnerability in wp-includes/wp-db.php in WordPress before 4.2.1 allows remote attackers to inject arbitrary web script or HTML via a long comment that is improperly stored because of limitations on the MySQL TEXT data type.

Published: 2015-08-03 Last update: 2026-06-16 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2015-3440 is rated High Exploit Risk (69.6/100): CVSS Medium severity, with high exploitation likelihood (EPSS 17.87%, 97th percentile). Core evidence: 5 public exploit reference(s) are indexed (Exploit-DB). EPSS rose +3.48% over the last day, indicating growing attacker interest. Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Public exploit references (Exploit-DB) for CVE-2015-3440

EDB-ID Source Kind Published Link
36844 exploit_db edb 2015-04-27 Exploit-DB ↗
nvd_ref exploit_tag Exploit-DB ↗
nvd_ref exploit_tag Exploit-DB ↗
nvd_ref exploit_tag Exploit-DB ↗
nvd_ref exploit_tag Exploit-DB ↗

Exploit prediction scoring system (EPSS) score for CVE-2015-3440

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-15 14.39% 17.87% +3.48%
2 2026-04-18 10.81% 14.39% +3.58%
3 2026-03-04 10.81%

Full EPSS history (48 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2015-3440

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
4.3 2.0 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:M)
Exploitation needs some favorable conditions, but not exceptional ones.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:N)
No confidentiality impact.
Integrity impact (I:P)
Partial integrity impact.
Availability impact (A:N)
No availability impact.
8.6 2.9 [email protected]

Weakness enumeration for CVE-2015-3440

OS Trackers for CVE-2015-3440

vendor priority summary link
debian not yet assigned CVE-2015-3440 not yet assigned priority: Debian including 1 source packages (wordpress), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. https://security-tracker.debian.org/tracker/CVE-2015-3440
ubuntu high CVE-2015-3440 high priority: Ubuntu including 1 source packages (wordpress), 14 status rows across 14 suites (artful, bionic, cosmic, disco, lucid, precise, trusty, upstream, utopic, vivid, wily, xenial, yakkety, zesty): ignored 8, not-affected 4, DNE 1, released 1. https://ubuntu.com/security/CVE-2015-3440

Affected software / configurations for CVE-2015-3440

Vendor Product Version Raw CPE
debian debian_linux 7.0 cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
debian debian_linux 8.0 cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
wordpress wordpress <= 4.2 cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*

References for CVE-2015-3440

URL Tags
http://codex.wordpress.org/Version_4.2.1
http://lists.fedoraproject.org/pipermail/package-announce/2015-May/157391.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-May/158271.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-May/158278.html
http://osvdb.org/show/osvdb/121320
http://packetstormsecurity.com/files/131644/WordPress-4.2-Cross-Site-Scripting.html Exploit
http://seclists.org/fulldisclosure/2015/Apr/84 Exploit
http://www.debian.org/security/2015/dsa-3250
http://www.securityfocus.com/bid/74334
http://www.securitytracker.com/id/1032199
https://core.trac.wordpress.org/changeset/32299
https://klikki.fi/adv/wordpress2.html Exploit
https://wordpress.org/news/2015/04/wordpress-4-2-1/ Patch Vendor Advisory
https://wpvulndb.com/vulnerabilities/7945
https://www.exploit-db.com/exploits/36844/ Exploit
cvelogic Threat Intelligence