MEDIUM
Cross-site scripting (XSS) vulnerability in the Tweet Blender plugin before 4.0.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the tb_tab_index parameter to wp-admin/options-general.php
Published Nov 22, 2013
4.3
MEDIUMCVSS 2.0
EPSS 2.06%
Description
Cross-site scripting (XSS) vulnerability in the Tweet Blender plugin before 4.0.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the tb_tab_index parameter to wp-admin/options-general.php.
Affected products
No data.
OR
- ≤ 4.0.1
- 2.0.0
- 2.0.1
- 2.0.2
- 2.0.3
- 2.0.4
- 2.0.5
- 2.1.0
- 2.1.1
- 2.2.0
- 2.2.1
- 2.2.2
- 2.2.3
- 2.3.0
- 2.4.0
- 2.4.1
- 2.4.2
- 2.4.3
- 2.4.4
- 2.4.5
- 2.4.6
- 2.4.7
- 3.0.0
- 3.0.1
- 3.0.2
- 3.0.3
- 3.0.4
- 3.0.5
- 3.0.6
- 3.0.7
- 3.0.8
- 3.1.0
- 3.1.1
- 3.1.2
- 3.1.3
- 3.1.4
- 3.1.5
- 3.1.6
- 3.1.7
- 3.1.8
- 3.1.9
- 3.1.10
- 3.1.11
- 3.1.12
- 3.1.13
- 3.1.14
- 3.1.15
- 3.1.16
- 3.1.17
- 3.1.18
- 3.2.0
- 3.2.1
- 3.2.2
- 3.2.3
- 3.2.4
- 3.3.0
- 3.3.1
- 3.3.2
- 3.3.3
- 3.3.4
- 3.3.5
- 3.3.6
- 3.3.7
- 3.3.8
- 3.3.9
- 3.3.10
- 3.3.11
- 3.3.12
- 3.3.13
- 3.3.14
- 3.3.15
- 4.0.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- http://archives.neohapsis.com/archives/bugtraq/2013-11/0072.html mailing-listx_refsource_BUGTRAQExploit
- http://secunia.com/advisories/55780 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://wordpress.org/plugins/tweet-blender/changelog x_refsource_CONFIRMPatch
- https://www.htbridge.com/advisory/HTB23180 x_refsource_MISCExploit
| Link | Providers | Tags |
|---|---|---|
| http://archives.neohapsis.com/archives/bugtraq/2013-11/0072.html | mailing-listx_refsource_BUGTRAQExploit | |
| http://secunia.com/advisories/55780 | third-party-advisoryx_refsource_SECUNIAVendor Advisory | |
| http://wordpress.org/plugins/tweet-blender/changelog | x_refsource_CONFIRMPatch | |
| https://www.htbridge.com/advisory/HTB23180 | x_refsource_MISCExploit |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Nov 22, 2013
Updated Aug 6, 2024
Reserved Nov 1, 2013
Link CVE-2013-6342
CISA Vulnrichment
Updated n/a