CVE-2013-3254: XSS
Cross-site scripting (XSS) vulnerability in wp-admin/admin.php in the WP Photo Album Plus plugin before 5.0.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the commentid parameter in a wppamanagecomments edit action.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-3254?
CVE-2013-3254 has a moderate severity as it allows remote attackers to perform cross-site scripting attacks.
How do I fix CVE-2013-3254?
To fix CVE-2013-3254, upgrade the WP Photo Album Plus plugin to version 5.0.3 or later.
What is affected by CVE-2013-3254?
CVE-2013-3254 affects WP Photo Album Plus plugin versions before 5.0.3 running on WordPress.
How does CVE-2013-3254 exploit work?
CVE-2013-3254 allows attackers to inject arbitrary web script or HTML through the commentid parameter in a specific action.
Who is at risk from CVE-2013-3254?
Users of the WP Photo Album Plus plugin prior to version 5.0.3 on their WordPress sites are at risk from CVE-2013-3254.