Lucene search

K
cveFlexeraCVE-2013-3264
HistoryNov 05, 2013 - 8:55 p.m.

CVE-2013-3264

2013-11-0520:55:29
CWE-264
flexera
web.nvd.nist.gov
25
cve-2013-3264
security
wordpress
email marketer
access restriction

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:P/A:P

AI Score

7

Confidence

Low

EPSS

0.005

Percentile

75.8%

The WP Ultimate Email Marketer plugin 1.1.0 and possibly earlier for Wordpress does not properly restrict access to (1) list/edit.php and (2) campaign/editCampaign.php, which allows remote attackers to modify list or campaign data.

Affected configurations

Nvd
Node
smackcoderswp_ultimate_email_marketer_pluginRange1.1.0-wordpress
OR
smackcoderswp_ultimate_email_marketer_pluginMatch1.0.0-wordpress
OR
smackcoderswp_ultimate_email_marketer_pluginMatch1.0.1-wordpress
OR
smackcoderswp_ultimate_email_marketer_pluginMatch1.0.2-wordpress
OR
smackcoderswp_ultimate_email_marketer_pluginMatch1.0.3-wordpress
VendorProductVersionCPE
smackcoderswp_ultimate_email_marketer_plugin*cpe:2.3:a:smackcoders:wp_ultimate_email_marketer_plugin:*:-:*:*:*:wordpress:*:*
smackcoderswp_ultimate_email_marketer_plugin1.0.0cpe:2.3:a:smackcoders:wp_ultimate_email_marketer_plugin:1.0.0:-:*:*:*:wordpress:*:*
smackcoderswp_ultimate_email_marketer_plugin1.0.1cpe:2.3:a:smackcoders:wp_ultimate_email_marketer_plugin:1.0.1:-:*:*:*:wordpress:*:*
smackcoderswp_ultimate_email_marketer_plugin1.0.2cpe:2.3:a:smackcoders:wp_ultimate_email_marketer_plugin:1.0.2:-:*:*:*:wordpress:*:*
smackcoderswp_ultimate_email_marketer_plugin1.0.3cpe:2.3:a:smackcoders:wp_ultimate_email_marketer_plugin:1.0.3:-:*:*:*:wordpress:*:*

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:P/A:P

AI Score

7

Confidence

Low

EPSS

0.005

Percentile

75.8%

Related for CVE-2013-3264