Release date:
Updated on:
Affected Systems:
WordPress WP Symposium
Description:
--------------------------------------------------------------------------------
Bugtraq id: 59044
CVE (CAN) ID: CVE-2013-2695
WordPress WP Symposium plug-in is a network plug-in that adds social functions.
WP Symposium 13.02 does not properly filter user input, and a security vulnerability exists. Attackers can exploit this vulnerability to execute arbitrary scripts in the affected site user's browser.
<* Source: Charlie Eriksen
Link: http://www.securelist.com/en/advisories/52925
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
WordPress
---------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.wpsymposium.com/