Cross-Site Scripting Vulnerability in WP Ultimate Email Marketer Plugin by WordPress
CVE-2014-4600

Currently unrated

Key Information:

Vendor

Wordpress

Vendor
CVE Published:
2 July 2014

What is CVE-2014-4600?

The WP Ultimate Email Marketer plugin for WordPress contains multiple cross-site scripting (XSS) vulnerabilities that can be exploited by remote attackers. By manipulating the 'listname' or 'contact' parameters in the contact/edit.php file, attackers are able to inject arbitrary web scripts or HTML. This security flaw can lead to unauthorized actions and compromise user data, emphasizing the need for secure coding practices in plugin development.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.