SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2013-5739

The default configuration of WordPress before 3.6.1 does not prevent uploads of .swf and .exe files, which might make it easier for remote authenticated users to conduct cross-site scripting (XSS) attacks via a crafted file, related to the…

LOW 3.5EPSS 1.76%

Does this matter?

Lower severity and a low EPSS score (1.76%). Track it; it rarely justifies an emergency change on its own.

Description

The default configuration of WordPress before 3.6.1 does not prevent uploads of .swf and .exe files, which might make it easier for remote authenticated users to conduct cross-site scripting (XSS) attacks via a crafted file, related to the get_allowed_mime_types function in wp-includes/functions.php.

CVSS 2.0
3.5 LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
EPSS
1.76% probability · 77th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
wordpress/wordpress
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.