CVE-2013-4626
BackWPup <3.0.13 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in the BackWPup plugin before 3.0.13 for WordPress allows remote attackers to inject arbitrary web script or HTML via the tab parameter to wp-admin/admin.php.
References (5)
Scores
EPSS
0.0050
EPSS Percentile
65.6%
Details
CWE
CWE-79
Status
published
Products (15)
marketpress/backwpup_plugin
< 3.0.12
marketpress/backwpup_plugin
marketpress/backwpup_plugin
marketpress/backwpup_plugin
marketpress/backwpup_plugin
marketpress/backwpup_plugin
marketpress/backwpup_plugin
marketpress/backwpup_plugin
marketpress/backwpup_plugin
marketpress/backwpup_plugin
... and 5 more
Published
Sep 26, 2013
Tracked Since
Feb 18, 2026