Unrated severityNVD Advisory· Published Jan 30, 2020· Updated Aug 6, 2024
CVE-2013-4241
CVE-2013-4241
Description
Multiple cross-site scripting (XSS) vulnerabilities in the HMS Testimonials plugin before 2.0.11 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) image, (3) url, or (4) testimonial parameter to the Testimonial form (hms-testimonials-addnew page); (5) date_format parameter to the Settings - Default form (hms-testimonials-settings page); (6) name parameter in a Save action to the Settings - Custom Fields form (hms-testimonials-settings-fields page); or (7) name parameter in a Save action to the Settings - Template form (hms-testimonials-templates-new page).
Affected products
1- Range: before 2.0.11
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- seclists.org/fulldisclosure/2013/Aug/96mitrex_refsource_MISC
- seclists.org/fulldisclosure/2013/Aug/98mitrex_refsource_MISC
- seclists.org/oss-sec/2013/q3/345mitrex_refsource_MISC
- seclists.org/oss-sec/2013/q3/361mitrex_refsource_MISC
- wordpress.org/plugins/hms-testimonials/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.