CVE-2013-0734

Multiple cross-site scripting (XSS) vulnerabilities in the Mingle Forum plugin before 1.0.34 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) search_words parameter in a search action to wpf.class.php or (2) togroupusers parameter in an add_user_togroup action to fs-admin/fs-admin.php.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
flexeraCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 61%
VendorProductVersion
cartpaujmingle-forum
𝑥
≤ 1.0.33
cartpaujmingle-forum
1.0.00
cartpaujmingle-forum
1.0.01
cartpaujmingle-forum
1.0.02
cartpaujmingle-forum
1.0.03
cartpaujmingle-forum
1.0.04
cartpaujmingle-forum
1.0.05
cartpaujmingle-forum
1.0.06
cartpaujmingle-forum
1.0.07
cartpaujmingle-forum
1.0.08
cartpaujmingle-forum
1.0.09
cartpaujmingle-forum
1.0.10
cartpaujmingle-forum
1.0.11
cartpaujmingle-forum
1.0.12
cartpaujmingle-forum
1.0.13
cartpaujmingle-forum
1.0.14
cartpaujmingle-forum
1.0.15
cartpaujmingle-forum
1.0.16
cartpaujmingle-forum
1.0.17
cartpaujmingle-forum
1.0.18
cartpaujmingle-forum
1.0.19
cartpaujmingle-forum
1.0.20
cartpaujmingle-forum
1.0.21
cartpaujmingle-forum
1.0.21.1
cartpaujmingle-forum
1.0.22
cartpaujmingle-forum
1.0.23
cartpaujmingle-forum
1.0.23.1
cartpaujmingle-forum
1.0.23.2
cartpaujmingle-forum
1.0.24
cartpaujmingle-forum
1.0.25
cartpaujmingle-forum
1.0.26
cartpaujmingle-forum
1.0.27
cartpaujmingle-forum
1.0.28
cartpaujmingle-forum
1.0.28.1
cartpaujmingle-forum
1.0.28.2
cartpaujmingle-forum
1.0.29
cartpaujmingle-forum
1.0.30
cartpaujmingle-forum
1.0.31
cartpaujmingle-forum
1.0.31.1
cartpaujmingle-forum
1.0.31.2
cartpaujmingle-forum
1.0.31.3
cartpaujmingle-forum
1.0.31.4
cartpaujmingle-forum
1.0.32
cartpaujmingle-forum
1.0.32.1
𝑥
= Vulnerable software versions