4.3
CVSSv2

CVE-2013-2501

Published: 22/03/2013 Updated: 29/08/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the Terillion Reviews plugin prior to 1.2 for WordPress allows remote malicious users to inject arbitrary web script or HTML via the ProfileId field.

Vulnerable Product Search on Vulmon Subscribe to Product

terillion terillion_reviews_plugin

Exploits

source: wwwsecurityfocuscom/bid/58415/info The Terillion Reviews plugin for WordPress is prone to an HTML-injection vulnerability because it fails to properly sanitize user-supplied input before using it in dynamically generated content Successful exploits will allow attacker-supplied HTML and script code to run in the context of the af ...
WordPress Terillion Reviews plugin suffers from a persistent cross site scripting vulnerability ...