4.3
CVSSv2

CVE-2013-3529

Published: 10/05/2013 Updated: 29/08/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in user/obits.php in the WP FuneralPress plugin prior to 1.1.7 for WordPress allow remote malicious users to inject arbitrary web script or HTML via the (1) message, (2) photo-message, or (3) youtube-message parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

smartypantsplugins wp-funeral-press 1.1.4

smartypantsplugins wp-funeral-press 1.1.3

smartypantsplugins wp-funeral-press 1.0.3

smartypantsplugins wp-funeral-press 1.0.2

smartypantsplugins wp-funeral-press

smartypantsplugins wp-funeral-press 1.0.5

smartypantsplugins wp-funeral-press 1.0.4

smartypantsplugins wp-funeral-press 1.0.9

smartypantsplugins wp-funeral-press 1.0.7

smartypantsplugins wp-funeral-press 1.1.2

smartypantsplugins wp-funeral-press 1.1.0

smartypantsplugins wp-funeral-press 1.0.1

Exploits

# # # WP FuneralPress - stored xss in guestbook # # "FuneralPress is an online website obituary management and guest book program for funeral homes and cemeteries" # wpfuneralpresscom/ # # tested on: funeralpress version 116 / wordpress version 351 # # impact: # malicious script execution as wordpress administrator # # author: robarms ...