CVE
- Id
- 63476
- CVE No.
- CVE-2013-3529
- Status
- Candidate
- Description
- Multiple cross-site scripting (XSS) vulnerabilities in user/obits.php in the WP FuneralPress plugin before 1.1.7 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) message, (2) photo-message, or (3) youtube-message parameter.
- Phase
- Assigned (20130510)
- Votes
- None (candidate not yet proposed)
- Comments