Cross-site Scripting Vulnerability in prettyPhoto Plugin Affects WordPress
CVE-2013-6837

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
19 December 2013

What is CVE-2013-6837?

The prettyPhoto plugin, commonly used in WordPress for displaying images and videos in a lightbox format, contains a cross-site scripting vulnerability in its setTimeout function located in js/jquery.prettyPhoto.js. This flaw allows attackers to inject arbitrary web scripts or HTML through a crafted PATH_INTO parameter directed at the default URI. If exploited, this vulnerability could lead to unauthorized actions and data theft in the context of the affected web applications, compromising the integrity and security of user interactions.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.