CVE-2013-4240
Multiple cross-site request forgery (CSRF) vulnerabilities in the HMS Testimonials plugin before 2.0.11 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) add new testimonials via the hms-testimonials-addnew page, (2) add new groups via the hms-testimonials-addnewgroup page, (3) change default settings via the hms-testimonials-settings page, (4) change advanced settings via the hms-testimonials-settings-advanced page, (5) change custom fields settings via the hms-testimonials-settings-fields page, or (6) change template settings via the hms-testimonials-templates-new page to wp-admin/admin.php.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P
- Puntuación base: 6.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 2.83%
- Percentil entre todas las CVEs puntuadas: 86
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-352
Referencias
- http://osvdb.org/96107
- http://seclists.org/fulldisclosure/2013/Aug/96
- http://seclists.org/fulldisclosure/2013/Aug/98
- http://seclists.org/oss-sec/2013/q3/345
- http://seclists.org/oss-sec/2013/q3/361
- http://wordpress.org/plugins/hms-testimonials/changelog
- http://osvdb.org/96107
- http://seclists.org/fulldisclosure/2013/Aug/96
- http://seclists.org/fulldisclosure/2013/Aug/98
- http://seclists.org/oss-sec/2013/q3/345
- http://seclists.org/oss-sec/2013/q3/361
- http://wordpress.org/plugins/hms-testimonials/changelog
JSON original (NVD)
Mostrar
{
"id": "CVE-2013-4240",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.8,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"affected": [
{
"source": "secalert@redhat.com",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2014-04-02T16:05:50.407",
"references": [
{
"url": "http://osvdb.org/96107",
"source": "secalert@redhat.com"
},
{
"url": "http://seclists.org/fulldisclosure/2013/Aug/96",
"source": "secalert@redhat.com"
},
{
"url": "http://seclists.org/fulldisclosure/2013/Aug/98",
"source": "secalert@redhat.com"
},
{
"url": "http://seclists.org/oss-sec/2013/q3/345",
"source": "secalert@redhat.com"
},
{
"url": "http://seclists.org/oss-sec/2013/q3/361",
"source": "secalert@redhat.com"
},
{
"url": "http://wordpress.org/plugins/hms-testimonials/changelog",
"source": "secalert@redhat.com"
},
{
"url": "http://osvdb.org/96107",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://seclists.org/fulldisclosure/2013/Aug/96",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://seclists.org/fulldisclosure/2013/Aug/98",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://seclists.org/oss-sec/2013/q3/345",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://seclists.org/oss-sec/2013/q3/361",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://wordpress.org/plugins/hms-testimonials/changelog",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-352"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Multiple cross-site request forgery (CSRF) vulnerabilities in the HMS Testimonials plugin before 2.0.11 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) add new testimonials via the hms-testimonials-addnew page, (2) add new groups via the hms-testimonials-addnewgroup page, (3) change default settings via the hms-testimonials-settings page, (4) change advanced settings via the hms-testimonials-settings-advanced page, (5) change custom fields settings via the hms-testimonials-settings-fields page, or (6) change template settings via the hms-testimonials-templates-new page to wp-admin/admin.php."
},
{
"lang": "es",
"value": "Múltiples vulnerabilidades de CSRF en el plugin HMS Testimonials anterior a 2.0.11 para WordPress permiten a atacantes remotos secuestrar la autenticación de administradores para solicitudes que (1) añaden testimonios nuevos a través de la página hms-testimonials-addnew, (2) añaden grupos nuevos a través de la página hms-testimonials-addnewgroup, (3) cambian configuraciones por defecto a través de la página hms-testimonials-settings, (4) cambian configuraciones avanzadas a través de la página hms-testimonials-settings-advanced, (5) cambian configuraciones de campos personalizados a través de la página hms-testimonials-settings-fields o (6) cambian configuraciones de plantillas a través de la página hms-testimonials-templates-new hacia wp-admin/admin.php."
}
],
"lastModified": "2026-06-16T23:56:52.470",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:hitmyserver:hms_testimonials:*:*:*:*:*:wordpress:*:*",
"vulnerable": true,
"matchCriteriaId": "7A903854-09A5-4D79-AF19-F78AF3312C46",
"versionEndIncluding": "2.0.10"
},
{
"criteria": "cpe:2.3:a:hitmyserver:hms_testimonials:1.1:*:*:*:*:wordpress:*:*",
"vulnerable": true,
"matchCriteriaId": "C0281143-2C2D-4927-8AD7-439EB33757C6"
},
{
"criteria": "cpe:2.3:a:hitmyserver:hms_testimonials:1.2:*:*:*:*:wordpress:*:*",
"vulnerable": true,
"matchCriteriaId": "4F598A87-5922-41AC-A7B6-06D189D06648"
},
{
"criteria": "cpe:2.3:a:hitmyserver:hms_testimonials:1.3:*:*:*:*:wordpress:*:*",
"vulnerable": true,
"matchCriteriaId": "506DEDB4-B152-440F-98BF-4B777EADD824"
},
{
"criteria": "cpe:2.3:a:hitmyserver:hms_testimonials:1.4:*:*:*:*:wordpress:*:*",
"vulnerable": true,
"matchCriteriaId": "060FCCF4-DFE2-4165-B369-D68CD64F8759"
},
{
"criteria": "cpe:2.3:a:hitmyserver:hms_testimonials:1.4.1:*:*:*:*:wordpress:*:*",
"vulnerable": true,
"matchCriteriaId": "1AE7E3F9-7B56-4DCA-A295-06CCFD72521F"
},
{
"criteria": "cpe:2.3:a:hitmyserver:hms_testimonials:1.5:*:*:*:*:wordpress:*:*",
"vulnerable": true,
"matchCriteriaId": "9874964F-7FB4-4FD9-9B83-19E2775E526A"
},
{
"criteria": "cpe:2.3:a:hitmyserver:hms_testimonials:1.6:*:*:*:*:wordpress:*:*",
"vulnerable": true,
"matchCriteriaId": "2AEB8A09-DCBD-49BE-B637-E614B508B950"
},
{
"criteria": "cpe:2.3:a:hitmyserver:hms_testimonials:1.6.1:*:*:*:*:wordpress:*:*",
"vulnerable": true,
"matchCriteriaId": "5D8A4D96-EFE1-490D-B48C-4D197C38DB2D"
},
{
"criteria": "cpe:2.3:a:hitmyserver:hms_testimonials:1.6.2:*:*:*:*:wordpress:*:*",
"vulnerable": true,
"matchCriteriaId": "5B6D5536-F03B-4819-92D2-710740FE21EC"
},
{
"criteria": "cpe:2.3:a:hitmyserver:hms_testimonials:1.7:*:*:*:*:wordpress:*:*",
"vulnerable": true,
"matchCriteriaId": "A81C427B-F1A6-4BBA-B76F-6FBE67B288A3"
},
{
"criteria": "cpe:2.3:a:hitmyserver:hms_testimonials:1.7.1:*:*:*:*:wordpress:*:*",
"vulnerable": true,
"matchCriteriaId": "6E9A07D9-1CD9-4D5E-81DE-FAB76936776E"
},
{
"criteria": "cpe:2.3:a:hitmyserver:hms_testimonials:2.0:*:*:*:*:wordpress:*:*",
"vulnerable": true,
"matchCriteriaId": "234C301C-B115-4274-91D9-D477EEB3ECBA"
},
{
"criteria": "cpe:2.3:a:hitmyserver:hms_testimonials:2.0.1:*:*:*:*:wordpress:*:*",
"vulnerable": true,
"matchCriteriaId": "8472AF76-A706-4824-8ED2-A2925CB4B172"
},
{
"criteria": "cpe:2.3:a:hitmyserver:hms_testimonials:2.0.2:*:*:*:*:wordpress:*:*",
"vulnerable": true,
"matchCriteriaId": "E54A7190-EAA3-4B99-AD1E-34E47F59DADA"
},
{
"criteria": "cpe:2.3:a:hitmyserver:hms_testimonials:2.0.3:*:*:*:*:wordpress:*:*",
"vulnerable": true,
"matchCriteriaId": "0FB6965F-37A1-4BAD-A7E0-D57F7DF33336"
},
{
"criteria": "cpe:2.3:a:hitmyserver:hms_testimonials:2.0.4:*:*:*:*:wordpress:*:*",
"vulnerable": true,
"matchCriteriaId": "7F4E6A73-5DAE-4A20-946A-055C7D3BF1E3"
},
{
"criteria": "cpe:2.3:a:hitmyserver:hms_testimonials:2.0.5:*:*:*:*:wordpress:*:*",
"vulnerable": true,
"matchCriteriaId": "837DD2A5-3E1B-4DBE-A0EF-B399F11EC4FE"
},
{
"criteria": "cpe:2.3:a:hitmyserver:hms_testimonials:2.0.6:*:*:*:*:wordpress:*:*",
"vulnerable": true,
"matchCriteriaId": "373934E4-759E-4676-B77A-C0B5C9B5E338"
},
{
"criteria": "cpe:2.3:a:hitmyserver:hms_testimonials:2.0.7:*:*:*:*:wordpress:*:*",
"vulnerable": true,
"matchCriteriaId": "1D7C63A6-3B72-4F99-B086-E17A75EA2E55"
},
{
"criteria": "cpe:2.3:a:hitmyserver:hms_testimonials:2.0.8:*:*:*:*:wordpress:*:*",
"vulnerable": true,
"matchCriteriaId": "6D334838-2FA2-41C1-B821-78BF9F8DB198"
},
{
"criteria": "cpe:2.3:a:hitmyserver:hms_testimonials:2.0.9:*:*:*:*:wordpress:*:*",
"vulnerable": true,
"matchCriteriaId": "6FC68E33-B38E-4C90-ABA6-738410D47258"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "secalert@redhat.com"
}