SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2013-4954

Multiple cross-site scripting (XSS) vulnerabilities in wp-login.php in the Genetech Solutions Pie-Register plugin before 1.31 for WordPress, when "Allow New Registrations to set their own Password" is enabled, allow remote attackers to inject arbitrary…

LOW 2.6EPSS 6.15%

Does this matter?

Lower severity and a low EPSS score (6.15%). Track it; it rarely justifies an emergency change on its own.

Description

Multiple cross-site scripting (XSS) vulnerabilities in wp-login.php in the Genetech Solutions Pie-Register plugin before 1.31 for WordPress, when "Allow New Registrations to set their own Password" is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) pass1 or (2) pass2 parameter in a register action. NOTE: some of these details are obtained from third party information.

CVSS 2.0
2.6 LOWAV:N/AC:H/Au:N/C:N/I:P/A:N
EPSS
6.15% probability · 93th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
genetechsolutions/pie-register
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.