Cross-Site Scripting Vulnerability in WP Ultimate Email Marketer Plugin by WordPress
CVE-2014-4600
Currently unrated
What is CVE-2014-4600?
The WP Ultimate Email Marketer plugin for WordPress contains multiple cross-site scripting (XSS) vulnerabilities that can be exploited by remote attackers. By manipulating the 'listname' or 'contact' parameters in the contact/edit.php file, attackers are able to inject arbitrary web scripts or HTML. This security flaw can lead to unauthorized actions and compromise user data, emphasizing the need for secure coding practices in plugin development.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.