CVE-2013-7276: XSS
Published Jan 8, 2014
·Updated
Cross-site scripting (XSS) vulnerability in inc/rafform.php in the Recommend to a friend plugin 2.0.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the currenturl parameter.
Affected Software
4 affected components
Recommend To A Friend Project Recommend To A Friend=2.0.2
WordPress WordPress
All of the following
Recommend To A Friend Project Recommend To A Friend=2.0.2
WordPress WordPress
Event History
Jan 8, 2014
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·03:30 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2013-7276?
The severity of CVE-2013-7276 is rated as medium with a score of 4.3.
2
What type of vulnerability is CVE-2013-7276?
CVE-2013-7276 is identified as a cross-site scripting (XSS) vulnerability.
3
How can I fix CVE-2013-7276?
To fix CVE-2013-7276, update the Recommend to a Friend plugin to the latest version or remove the plugin if an update is not available.
4
What impact does CVE-2013-7276 have on my website?
CVE-2013-7276 allows remote attackers to inject arbitrary web script or HTML, potentially compromising user data.
5
Which software is affected by CVE-2013-7276?
CVE-2013-7276 affects the Recommend To A Friend plugin version 2.0.2 for WordPress.