VYPR
Unrated severityNVD Advisory· Published Mar 14, 2014· Updated May 6, 2026

CVE-2013-1758

CVE-2013-1758

Description

Marekkis Watermark plugin 0.9.2 for WordPress has an XSS flaw via the pfad parameter in wp-admin/options-general.php.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Marekkis Watermark plugin 0.9.2 for WordPress has an XSS flaw via the pfad parameter in wp-admin/options-general.php.

Vulnerability

The Marekkis Watermark plugin version 0.9.2 for WordPress contains a cross-site scripting (XSS) vulnerability in the pfad parameter passed to wp-admin/options-general.php. An attacker can inject arbitrary web script or HTML via this parameter [1]. The issue is exposed through the plugin's administrative interface.

Exploitation

An attacker must have network access to the WordPress admin area. No authentication level is specified, but the vulnerable endpoint (wp-admin/options-general.php) typically requires administrator privileges. The attacker sends a crafted request with malicious script or HTML in the pfad parameter; if the plugin fails to sanitize this input, the payload executes in the context of the victim's browser when the page is rendered [1].

Impact

Successful exploitation allows an attacker to inject arbitrary web script or HTML in the administrative context. This could lead to session hijacking, credential theft, or defacement of the WordPress admin interface, affecting the confidentiality and integrity of the WordPress instance [1].

Mitigation

As of the available references, no fixed version has been disclosed. Users should consider disabling the Marekkis Watermark plugin or applying web application firewall rules to sanitize the pfad parameter until a patch is released by the vendor [1].

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.