CVE-2013-3261
medium
CVSS v3
โ
CVSS v4 NEW
โ
VIR risk
4.3
Description
Cross-site scripting (XSS) vulnerability in wp-admin/admin.php in the GRAND FlAGallery plugin before 2.72 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter in a flag-manage-gallery action.
Predictions
Exploit likelihood
20%
Patch ETA
โ
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| photogallerycreator | flash-album-gallery | {"endIncluding":"2.71"} | |
| photogallerycreator | flash-album-gallery | 0.29 | |
| photogallerycreator | flash-album-gallery | 0.32 | |
| photogallerycreator | flash-album-gallery | 0.33 | |
| photogallerycreator | flash-album-gallery | 0.34 | |
| photogallerycreator | flash-album-gallery | 0.35 | |
| photogallerycreator | flash-album-gallery | 0.36 | |
| photogallerycreator | flash-album-gallery | 0.37 | |
| photogallerycreator | flash-album-gallery | 0.38 | |
| photogallerycreator | flash-album-gallery | 0.39 | |
| photogallerycreator | flash-album-gallery | 0.40 | |
| photogallerycreator | flash-album-gallery | 0.41 | |
| photogallerycreator | flash-album-gallery | 0.42 | |
| photogallerycreator | flash-album-gallery | 0.43 | |
| photogallerycreator | flash-album-gallery | 0.44 | |
| photogallerycreator | flash-album-gallery | 0.45 | |
| photogallerycreator | flash-album-gallery | 0.46 | |
| photogallerycreator | flash-album-gallery | 0.49 | |
| photogallerycreator | flash-album-gallery | 0.50 | |
| photogallerycreator | flash-album-gallery | 0.52 | |
| photogallerycreator | flash-album-gallery | 0.53 | |
| photogallerycreator | flash-album-gallery | 0.54 | |
| photogallerycreator | flash-album-gallery | 0.55 | |
| photogallerycreator | flash-album-gallery | 0.56 | |
| photogallerycreator | flash-album-gallery | 0.57 | |
| photogallerycreator | flash-album-gallery | 0.58 | |
| photogallerycreator | flash-album-gallery | 0.59 | |
| photogallerycreator | flash-album-gallery | 0.60 | |
| photogallerycreator | flash-album-gallery | 0.61 | |
| photogallerycreator | flash-album-gallery | 1.11 | |
| photogallerycreator | flash-album-gallery | 1.12 | |
| photogallerycreator | flash-album-gallery | 1.13 | |
| photogallerycreator | flash-album-gallery | 1.20 | |
| photogallerycreator | flash-album-gallery | 1.21 | |
| photogallerycreator | flash-album-gallery | 1.22 | |
| photogallerycreator | flash-album-gallery | 1.23 | |
| photogallerycreator | flash-album-gallery | 1.31 | |
| photogallerycreator | flash-album-gallery | 1.32 | |
| photogallerycreator | flash-album-gallery | 1.33 | |
| photogallerycreator | flash-album-gallery | 1.40 | |
| photogallerycreator | flash-album-gallery | 1.41 | |
| photogallerycreator | flash-album-gallery | 1.42 | |
| photogallerycreator | flash-album-gallery | 1.43 | |
| photogallerycreator | flash-album-gallery | 1.44 | |
| photogallerycreator | flash-album-gallery | 1.45 | |
| photogallerycreator | flash-album-gallery | 1.47 | |
| photogallerycreator | flash-album-gallery | 1.48 | |
| photogallerycreator | flash-album-gallery | 1.49 | |
| photogallerycreator | flash-album-gallery | 1.50 | |
| photogallerycreator | flash-album-gallery | 1.51 | |
| photogallerycreator | flash-album-gallery | 1.52 | |
| photogallerycreator | flash-album-gallery | 1.53 | |
| photogallerycreator | flash-album-gallery | 1.54 | |
| photogallerycreator | flash-album-gallery | 1.55 | |
| photogallerycreator | flash-album-gallery | 1.56 | |
| photogallerycreator | flash-album-gallery | 1.57 | |
| photogallerycreator | flash-album-gallery | 1.58 | |
| photogallerycreator | flash-album-gallery | 1.59 | |
| photogallerycreator | flash-album-gallery | 1.60 | |
| photogallerycreator | flash-album-gallery | 1.61 | |
| photogallerycreator | flash-album-gallery | 1.62 | |
| photogallerycreator | flash-album-gallery | 1.63 | |
| photogallerycreator | flash-album-gallery | 1.64 | |
| photogallerycreator | flash-album-gallery | 1.65 | |
| photogallerycreator | flash-album-gallery | 1.66 | |
| photogallerycreator | flash-album-gallery | 1.67 | |
| photogallerycreator | flash-album-gallery | 1.70 | |
| photogallerycreator | flash-album-gallery | 1.71 | |
| photogallerycreator | flash-album-gallery | 1.72 | |
| photogallerycreator | flash-album-gallery | 1.73 | |
| photogallerycreator | flash-album-gallery | 1.74 | |
| photogallerycreator | flash-album-gallery | 1.75 | |
| photogallerycreator | flash-album-gallery | 1.76 | |
| photogallerycreator | flash-album-gallery | 1.77 | |
| photogallerycreator | flash-album-gallery | 1.78 | |
| photogallerycreator | flash-album-gallery | 1.79 | |
| photogallerycreator | flash-album-gallery | 1.80 | |
| photogallerycreator | flash-album-gallery | 1.81 | |
| photogallerycreator | flash-album-gallery | 1.82 | |
| photogallerycreator | flash-album-gallery | 1.83 | |
| photogallerycreator | flash-album-gallery | 1.84 | |
| photogallerycreator | flash-album-gallery | 1.85 | |
| photogallerycreator | flash-album-gallery | 1.90 | |
| photogallerycreator | flash-album-gallery | 2.00 | |
| photogallerycreator | flash-album-gallery | 2.10 | |
| photogallerycreator | flash-album-gallery | 2.11 | |
| photogallerycreator | flash-album-gallery | 2.12 | |
| photogallerycreator | flash-album-gallery | 2.14 | |
| photogallerycreator | flash-album-gallery | 2.15 | |
| photogallerycreator | flash-album-gallery | 2.16 | |
| photogallerycreator | flash-album-gallery | 2.17 | |
| photogallerycreator | flash-album-gallery | 2.18 | |
| photogallerycreator | flash-album-gallery | 2.50 | |
| photogallerycreator | flash-album-gallery | 2.51 | |
| photogallerycreator | flash-album-gallery | 2.52 | |
| photogallerycreator | flash-album-gallery | 2.53 | |
| photogallerycreator | flash-album-gallery | 2.54 | |
| photogallerycreator | flash-album-gallery | 2.55 | |
| photogallerycreator | flash-album-gallery | 2.56 | |
| photogallerycreator | flash-album-gallery | 2.70 | |
| wordpress | wordpress | - | |
References
CWEs
CWE-79
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.