SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2013-3263

Multiple cross-site scripting (XSS) vulnerabilities in the WP Ultimate Email Marketer plugin 1.1.0 and possibly earlier for Wordpress allow remote attackers to inject arbitrary web script or HTML via the (1) siteurl parameter to…

MEDIUM 4.3EPSS 1.60%

Does this matter?

Lower severity and a low EPSS score (1.60%). Track it; it rarely justifies an emergency change on its own.

Description

Multiple cross-site scripting (XSS) vulnerabilities in the WP Ultimate Email Marketer plugin 1.1.0 and possibly earlier for Wordpress allow remote attackers to inject arbitrary web script or HTML via the (1) siteurl parameter to campaign/campaignone.php; the (2) action, (3) campaignname, (4) campaignformat, or (5) emailtemplate parameter to campaign/campaigntwo.php; the (6) listid parameter to list/edit.php; the (7) campaignid or (8) siteurl parameter to campaign/editcampaign.php; the (9) campaignid parameter to campaign/selectlistb4send.php; the (10) campaignid, (11) campaignname, (12) campaignsubject, or (13) selectedcampaigns parameter to campaign/sendCampaign.php; or the (14) campaignid, (15) campaignname, (16) campaignformat, or (17) action parameter to campaign/updatecampaign.php.

CVSS 2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS
1.60% probability · 74th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
smackcoders/wp ultimate email marketer plugin
Source
PSIRT-CNA@flexerasoftware.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.