Cross-site Scripting Vulnerability in CommentLuv Plugin for WordPress
CVE-2013-1409

Currently unrated

Key Information:

Vendor

Wordpress

Vendor
CVE Published:
3 March 2014

What is CVE-2013-1409?

A Cross-site Scripting (XSS) vulnerability exists in the CommentLuv plugin for WordPress, specifically in versions prior to 2.92.4. This flaw allows remote attackers to exploit the _ajax_nonce parameter in wp-admin/admin-ajax.php, which could enable malicious actors to inject arbitrary web scripts or HTML. This vulnerability can compromise the security of WordPress sites and potentially expose user data.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.