MailUp newsletter sign-up form [wp-mailup] < 1.3.3 (closed)
unknown
[en] ajax.functions.php in the MailUp plugin before 1.3.3 for WordPress does not properly restrict access to unspecified Ajax functions, which allows remote attackers to modify plugin settings and conduct cross-site scripting (XSS) attacks by setting the wordpress_logged_in cookie. NOTE: this is due to an incomplete f...
- Affected:
- up to 1.3.3
- Fixed in:
- 1.3.3
- Disclosed:
- Mar 22, 2013
CVE-2013-0731 on NVD →
MailUp newsletter sign-up form [wp-mailup] < 1.3.3 (closed)
unknown
[en] ajax.functions.php in the MailUp plugin before 1.3.2 for WordPress does not properly restrict access to unspecified Ajax functions, which allows remote attackers to modify plugin settings and conduct cross-site scripting (XSS) attacks via unspecified vectors related to "formData=save" requests, a different version...
- Affected:
- up to 1.3.3
- Fixed in:
- 1.3.3
- Disclosed:
- Mar 22, 2013
CVE-2013-2640 on NVD →
MailUp newsletter sign-up form < 1.3.2 - Cross-Site Scripting
medium
ajax.functions.php in the MailUp plugin before 1.3.2 for WordPress does not properly restrict access to unspecified Ajax functions, which allows remote attackers to modify plugin settings and conduct cross-site scripting (XSS) attacks via unspecified vectors related to "formData=save" requests, a different version than...
- CVSS:
- 6.4
- Affected:
- up to 1.3.2
- Fixed in:
- 1.3.2
- Disclosed:
- Mar 15, 2013
CVE-2013-2640 on NVD →
MailUp newsletter sign-up form < 1.3.3 - Cross-Site Scripting
medium
ajax.functions.php in the MailUp plugin before 1.3.3 for WordPress does not properly restrict access to unspecified Ajax functions, which allows remote attackers to modify plugin settings and conduct cross-site scripting (XSS) attacks by setting the wordpress_logged_in cookie. NOTE: this is due to an incomplete fix fo...
- CVSS:
- 6.1
- Affected:
- up to 1.3.3
- Fixed in:
- 1.3.3
- Disclosed:
- Mar 13, 2013
CVE-2013-0731 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database