Sploitus

CVE-2013-1407

2 known exploits for CVE-2013-1407

Multiple cross-site scripting (XSS) vulnerabilities in the Events Manager plugin before 5.3.5 and Events Manager Pro plugin before 2.2.9 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) scope parameter to index.php; (2) user_name, (3) dbem_phone, (4) user_email, or (5) booking_comment parameter to an event with registration enabled; or the (6) _wpnonce parameter to wp-admin/edit.php.

Netweblogic Events Manager
≤ 5.3.4, 5.3, 5.3.1, 5.3.2, 5.3.2.1, 5.3.3
Fix
Available
CVSS 2.0
4.3 MEDIUM
EPSS
2.1% (80th percentile)
Weakness
CWE-79
NVD status
Modified
Published
2014-05-13
CVE-2013-1407 at NVD
Authoritative description, scoring and affected products

2 known exploits for CVE-2013-1407

Proof-of-concept code and exploit modules indexed by Sploitus