CVE-2013-4626
Cross-site scripting (XSS) vulnerability in the BackWPup plugin before 3.0.13 for WordPress allows remote attackers to inject arbitrary web script or HTML via the tab parameter to wp-admin/admin.php.
- Affected products
- Backwpup
- Marketpress Backwpup Plugin
- ≤ 3.0.12, 3.0, 3.0.1, 3.0.2, 3.0.3, 3.0.4, 3.0.5, 3.0.6, 3.0.7, 3.0.8, 3.0.9, 3.0.10, 3.0.11
- Fix
- Available
- CVSS 2.0
- 4.3 MEDIUM
- EPSS
- 2.1% (80th percentile)
- Weakness
- CWE-79
- NVD status
- Modified
- Published
- 2013-09-26
CVE-2013-4626 at NVD
2 known exploits for CVE-2013-4626
Proof-of-concept code and exploit modules indexed by Sploitus