CVE-2013-2640

NONE

ajax.functions.php in the MailUp plugin before 1.3.2 for WordPress does not properly restrict access to unspecified Ajax functions, which allows remote attackers to modify plugin settings and conduct

公開日: 3/22/2013更新日: 4/11/2025

説明

ajax.functions.php in the MailUp plugin before 1.3.2 for WordPress does not properly restrict access to unspecified Ajax functions, which allows remote attackers to modify plugin settings and conduct cross-site scripting (XSS) attacks via unspecified vectors related to "formData=save" requests, a different version than CVE-2013-0731.

AI分析AIによる分析

影響を受ける製品

mailupwp-mailup
mailupwp-mailup
1.0.0
mailupwp-mailup
1.1.0
mailupwp-mailup
1.1.1
mailupwp-mailup
1.1.2
mailupwp-mailup
1.1.3
mailupwp-mailup
1.2
mailupwp-mailup
1.3
mailupwp-mailup
1.21
wordpresswordpress
-

参照