CVE-2013-2501
Terillion Reviews <1.2 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in the Terillion Reviews plugin before 1.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the ProfileId field.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Aditya Balapure · textwebappsphp
https://www.exploit-db.com/exploits/38373
References (7)
Scores
EPSS
0.0621
EPSS Percentile
90.8%
Details
CWE
CWE-79
Status
published
Products (2)
terillion/terillion_reviews_plugin
< 1.1
n/a/n/a
Published
Mar 22, 2013
Tracked Since
Feb 18, 2026