PT-2013-2566 · WordPress · Mailup Plugin For Wordpress

Published

2013-03-22

·

Updated

2017-08-29

·

CVE-2013-0731

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions MailUp plugin for WordPress versions prior to 1.3.3
Description The issue allows remote attackers to modify plugin settings and conduct cross-site scripting (XSS) attacks by setting the wordpress logged in cookie, due to incomplete access restriction to unspecified Ajax functions in the ajax.functions.php file. This is a result of an incomplete fix for a similar issue that was previously addressed.
Recommendations For MailUp plugin for WordPress versions prior to 1.3.3, update to version 1.3.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the ajax.functions.php file to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-0731

Affected Products

Mailup Plugin For Wordpress