Unrated severityNVD Advisory· Published Jul 8, 2013· Updated Apr 29, 2026
CVE-2013-0237
CVE-2013-0237
Description
Cross-site scripting (XSS) vulnerability in Plupload.as in Moxiecode plupload before 1.5.5, as used in WordPress before 3.5.1 and other products, allows remote attackers to inject arbitrary web script or HTML via the id parameter.
Affected products
89cpe:2.3:a:moxiecode:plupload:*:*:*:*:*:*:*:*+ 9 more
- cpe:2.3:a:moxiecode:plupload:*:*:*:*:*:*:*:*range: <=1.5.4
- cpe:2.3:a:moxiecode:plupload:1.4.0:*:*:*:*:*:*:*
- cpe:2.3:a:moxiecode:plupload:1.4.1:*:*:*:*:*:*:*
- cpe:2.3:a:moxiecode:plupload:1.4.2:*:*:*:*:*:*:*
- cpe:2.3:a:moxiecode:plupload:1.4.3:*:*:*:*:*:*:*
- cpe:2.3:a:moxiecode:plupload:1.5.0:*:*:*:*:*:*:*
- cpe:2.3:a:moxiecode:plupload:1.5.0:beta:*:*:*:*:*:*
- cpe:2.3:a:moxiecode:plupload:1.5.1:*:*:*:*:*:*:*
- cpe:2.3:a:moxiecode:plupload:1.5.2:*:*:*:*:*:*:*
- cpe:2.3:a:moxiecode:plupload:1.5.3:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*+ 75 more
- cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*range: <=3.5.0
- cpe:2.3:a:wordpress:wordpress:0.71:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:1.0:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:1.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:1.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:1.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:1.2:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:1.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:1.2.2:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:1.2.3:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:1.2.4:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:1.2.5:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:1.2.5:a:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:1.3:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:1.3.2:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:1.3.3:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:1.5:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:1.5.1:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:1.5.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:1.5.1.2:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:1.5.1.3:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:1.5.2:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:1.6.2:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:2.0:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:2.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:2.0.10:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:2.0.11:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:2.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:2.0.4:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:2.0.5:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:2.0.6:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:2.0.7:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:2.0.8:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:2.0.9:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:2.1:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:2.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:2.1.2:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:2.1.3:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:2.2:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:2.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:2.2.2:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:2.2.3:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:2.3:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:2.3.1:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:2.3.2:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:2.3.3:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:2.5:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:2.5.1:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:2.6:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:2.6.1:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:2.6.2:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:2.6.3:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:2.6.5:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:2.7:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:2.7.1:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:2.8:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:2.8.1:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:2.8.2:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:2.8.3:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:2.8.4:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:2.8.4:a:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:2.8.5:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:2.8.5.1:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:2.8.5.2:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:2.8.6:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:2.9:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:2.9.1:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:2.9.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:2.9.2:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:3.3:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:3.3.1:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:3.3.2:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:3.3.3:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:3.4.0:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:3.4.1:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:3.4.2:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:16:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:fedoraproject:fedora:16:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:17:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:18:*:*:*:*:*:*:*
Patches
12d746ee9083chttps://github.com/moxiecode/pluploadvia nvd-ref
Vulnerability mechanics
Generated by null/stub on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.
References
4News mentions
0No linked articles in our index yet.