### [CVE-2015-4582](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4582) ![](https://img.shields.io/static/v1?label=Product&message=boot-store&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=1.6.4%20&color=brightgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-79%20Improper%20Neutralization%20of%20Input%20During%20Web%20Page%20Generation%20('Cross-site%20Scripting')&color=brightgreen) ### Description The TheCartPress boot-store (aka Boot Store) theme 1.6.4 for WordPress allows header.php tcp_register_error XSS. NOTE: CVE-2015-4582 is not assigned to any Oracle product. ### POC #### Reference No PoCs from references. #### Github - https://github.com/dinosn/weblogic - https://github.com/safe6Sec/wlsEnv