CVE-2013-5978
Multiple cross-site scripting (XSS) vulnerabilities in products.php in the Cart66 Lite plugin before 1.5.1.15 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) Product name or (2) Price description fields via a…
Does this matter?
Lower severity and a low EPSS score (4.08%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site scripting (XSS) vulnerabilities in products.php in the Cart66 Lite plugin before 1.5.1.15 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) Product name or (2) Price description fields via a request to wp-admin/admin.php. NOTE: This issue may only cross privilege boundaries if used in combination with CVE-2013-5977.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 4.08% probability · 90th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- cart66/cart66 lite plugin
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2013-10/0048.htmlBroken Link
- http://packetstormsecurity.com/files/123587/WordPress-Cart66-1.5.1.14-Cross-Site-Request-Forgery-Cross-Site-Scripting.htmlExploit, Third Party Advisory, VDB Entry
- http://seclists.org/bugtraq/2013/Oct/52Mailing List, Third Party Advisory
- http://wordpress.org/plugins/cart66-lite/changelogRelease Notes, Third Party Advisory
- http://www.exploit-db.com/exploits/28959Exploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/62977Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/87873Third Party Advisory, VDB Entry
- http://archives.neohapsis.com/archives/bugtraq/2013-10/0048.htmlBroken Link
- http://packetstormsecurity.com/files/123587/WordPress-Cart66-1.5.1.14-Cross-Site-Request-Forgery-Cross-Site-Scripting.htmlExploit, Third Party Advisory, VDB Entry
- http://seclists.org/bugtraq/2013/Oct/52Mailing List, Third Party Advisory
- http://wordpress.org/plugins/cart66-lite/changelogRelease Notes, Third Party Advisory
- http://www.exploit-db.com/exploits/28959Exploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/62977Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/87873Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.