CVE-2013-2287

NUCLEI

Roberta Bramski Uploader - XSS

Title source: rule

Description

Multiple cross-site scripting (XSS) vulnerabilities in views/notify.php in the Uploader plugin 1.0.4 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) notify or (2) blog parameter.

Exploits (1)

exploitdb WRITEUP VERIFIED
by CodeV · textwebappsphp
https://www.exploit-db.com/exploits/38355

Nuclei Templates (1)

WordPress Plugin Uploader 1.0.4 - Cross-Site Scripting
MEDIUMby daffainfo

Scores

EPSS 0.0921
EPSS Percentile 92.6%

Details

CWE
CWE-79
Status published
Products (2)
roberta_bramski/uploader
n/a/n/a
Published Apr 04, 2014
Tracked Since Feb 18, 2026