CVE-2013-1409
published 2014-03-03CVE-2013-1409: Cross-site scripting (XSS) vulnerability in the CommentLuv plugin before 2.92.4 for WordPress allows remote attackers to inject arbitrary web script or HTML…
PriorityP423medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EXPLOIT
EPSS
4.55%
90.4th percentile
Cross-site scripting (XSS) vulnerability in the CommentLuv plugin before 2.92.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the _ajax_nonce parameter to wp-admin/admin-ajax.php.
Affected
52 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| commentluv | commentluv | <= 2.92.3 | — |
| commentluv | commentluv | — | — |
| commentluv | commentluv | — | — |
| commentluv | commentluv | — | — |
| commentluv | commentluv | — | — |
| commentluv | commentluv | — | — |
| commentluv | commentluv | — | — |
| commentluv | commentluv | — | — |
| commentluv | commentluv | — | — |
| commentluv | commentluv | — | — |
| commentluv | commentluv | — | — |
| commentluv | commentluv | — | — |
| commentluv | commentluv | — | — |
| commentluv | commentluv | — | — |
| commentluv | commentluv | — | — |
| commentluv | commentluv | — | — |
| commentluv | commentluv | — | — |
| commentluv | commentluv | — | — |
| commentluv | commentluv | — | — |
| commentluv | commentluv | — | — |
| commentluv | commentluv | — | — |
| commentluv | commentluv | — | — |
| commentluv | commentluv | — | — |
| commentluv | commentluv | — | — |
| commentluv | commentluv | — | — |
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No writeups or analysis indexed.
http://archives.neohapsis.com/archives/bugtraq/2013-02/0031.htmlhttp://osvdb.org/89925http://packetstormsecurity.com/files/120090/WordPress-CommentLuv-2.92.3-Cross-Site-Scripting.htmlhttp://wordpress.org/plugins/commentluv/changeloghttps://www.htbridge.com/advisory/HTB23138http://archives.neohapsis.com/archives/bugtraq/2013-02/0031.htmlhttp://osvdb.org/89925http://packetstormsecurity.com/files/120090/WordPress-CommentLuv-2.92.3-Cross-Site-Scripting.htmlhttp://wordpress.org/plugins/commentluv/changeloghttps://www.htbridge.com/advisory/HTB23138
2014-03-03
Published