VulnerabilityModified
CVE-2014-4600
Multiple cross-site scripting (XSS) vulnerabilities in contact/edit.php in the WP Ultimate Email Marketer plugin 1.1.0 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) listname or (2) contact parameter.
MEDIUM 4.3EPSS 1.62%
Does this matter?
Lower severity and a low EPSS score (1.62%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site scripting (XSS) vulnerabilities in contact/edit.php in the WP Ultimate Email Marketer plugin 1.1.0 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) listname or (2) contact parameter.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.62% probability · 75th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- wp ultimate email marketer project/wp ultimate email marketer
- Source
- cve@mitre.org
References
- http://codevigilant.com/disclosure/wp-plugin-wp-ultimate-email-marketer-a3-cross-site-scripting-xssExploit
- http://plugins.svn.wordpress.org/wp-ultimate-email-marketer/trunk/Readme.txt
- http://codevigilant.com/disclosure/wp-plugin-wp-ultimate-email-marketer-a3-cross-site-scripting-xssExploit
- http://plugins.svn.wordpress.org/wp-ultimate-email-marketer/trunk/Readme.txt
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.