PT-2013-3867 · WordPress · Mailup Plugin

Published

2013-03-22

·

Updated

2013-04-05

·

CVE-2013-2640

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions MailUp plugin for WordPress versions prior to 1.3.2
Description The issue allows remote attackers to modify plugin settings and conduct cross-site scripting (XSS) attacks. This is due to the ajax.functions.php file not properly restricting access to unspecified Ajax functions, related to "formData=save" requests.
Recommendations For MailUp plugin for WordPress versions prior to 1.3.2, update to version 1.3.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the Ajax functions in ajax.functions.php to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-2640

Affected Products

Mailup Plugin