CVE-2013-3529
10.05.2013, 21:55
Multiple cross-site scripting (XSS) vulnerabilities in user/obits.php in the WP FuneralPress plugin before 1.1.7 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) message, (2) photo-message, or (3) youtube-message parameter.
Vendor | Product | Version |
---|---|---|
smartypantsplugins | wp-funeral-press | 𝑥 ≤ 1.1.6 |
smartypantsplugins | wp-funeral-press | 1.0.1 |
smartypantsplugins | wp-funeral-press | 1.0.2 |
smartypantsplugins | wp-funeral-press | 1.0.3 |
smartypantsplugins | wp-funeral-press | 1.0.4 |
smartypantsplugins | wp-funeral-press | 1.0.5 |
smartypantsplugins | wp-funeral-press | 1.0.7 |
smartypantsplugins | wp-funeral-press | 1.0.9 |
smartypantsplugins | wp-funeral-press | 1.1.0 |
smartypantsplugins | wp-funeral-press | 1.1.2 |
smartypantsplugins | wp-funeral-press | 1.1.3 |
smartypantsplugins | wp-funeral-press | 1.1.4 |
𝑥
= Vulnerable software versions
References