First published: Tue Nov 05 2013(Updated: )
The WP Ultimate Email Marketer plugin 1.1.0 and possibly earlier for Wordpress does not properly restrict access to (1) list/edit.php and (2) campaign/editCampaign.php, which allows remote attackers to modify list or campaign data.
Credit: PSIRT-CNA@flexerasoftware.com
Affected Software | Affected Version | How to fix |
---|---|---|
Smackcoders Wp Ultimate Email Marketer Plugin | <=1.1.0 | |
Smackcoders Wp Ultimate Email Marketer Plugin | =1.0.0 | |
Smackcoders Wp Ultimate Email Marketer Plugin | =1.0.1 | |
Smackcoders Wp Ultimate Email Marketer Plugin | =1.0.2 | |
Smackcoders Wp Ultimate Email Marketer Plugin | =1.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2013-3264 is considered to be medium risk due to unauthorized access allowing modification of list or campaign data.
To fix CVE-2013-3264, update the WP Ultimate Email Marketer plugin to version 1.1.1 or newer as the vulnerability is addressed in these updates.
CVE-2013-3264 affects WP Ultimate Email Marketer plugin versions 1.1.0 and earlier.
CVE-2013-3264 is a security vulnerability that allows remote attackers to gain unauthorized access to modify data.
If CVE-2013-3264 is exploited, attackers could alter email marketing lists or campaigns, potentially leading to data loss or malicious content dissemination.