Cross-site Scripting Vulnerability in prettyPhoto Plugin Affects WordPress
CVE-2013-6837
Currently unrated
What is CVE-2013-6837?
The prettyPhoto plugin, commonly used in WordPress for displaying images and videos in a lightbox format, contains a cross-site scripting vulnerability in its setTimeout function located in js/jquery.prettyPhoto.js. This flaw allows attackers to inject arbitrary web scripts or HTML through a crafted PATH_INTO parameter directed at the default URI. If exploited, this vulnerability could lead to unauthorized actions and data theft in the context of the affected web applications, compromising the integrity and security of user interactions.