5

CVE-2013-2640

Exploit

MailUp newsletter sign-up form < 1.3.2 - Cross-Site Scripting

ajax.functions.php in the MailUp plugin before 1.3.2 for WordPress does not properly restrict access to unspecified Ajax functions, which allows remote attackers to modify plugin settings and conduct cross-site scripting (XSS) attacks via unspecified vectors related to "formData=save" requests, a different version than CVE-2013-0731.
Mögliche Gegenmaßnahme
MailUp newsletter sign-up form: Update to version 1.3.2, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MailupWp-mailup Version <= 1.3.1
   WordpressWordpress Version-
MailupWp-mailup Version1.0.0
   WordpressWordpress Version-
MailupWp-mailup Version1.1.0
   WordpressWordpress Version-
MailupWp-mailup Version1.1.1
   WordpressWordpress Version-
MailupWp-mailup Version1.1.2
   WordpressWordpress Version-
MailupWp-mailup Version1.1.3
   WordpressWordpress Version-
MailupWp-mailup Version1.2
   WordpressWordpress Version-
MailupWp-mailup Version1.3
   WordpressWordpress Version-
MailupWp-mailup Version1.21
   WordpressWordpress Version-
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt MailUp newsletter sign-up form
Version [*, 1.3.2)
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.38% 0.817
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://osvdb.org/91274
http://plugins.trac.wordpress.org/changeset?new=682420
Patch
Exploit
http://secunia.com/advisories/51917
Vendor Advisory
http://wordpress.org/extend/plugins/wp-mailup/changelog/
https://www.wordfence.com/threat-intel/vulnerabilities/id/20227433-a2f0-4a00-b6cc-95708135c0b8
Third Party Advisory