CVE-2013-1409: Commentluv
Medium severity, CVSS 4.3. EPSS: 4.5% chance of exploitation in the next 30 days.
Cross-site scripting (XSS) vulnerability in the CommentLuv plugin before 2.92.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the _ajax_nonce parameter to wp-admin/admin-ajax.php.
Affected products
- Commentluv Commentluv: up to and including 2.92.3; version 2.7 only; version 2.71 only; version 2.74 only; version 2.76 only; version 2.80 only; …
Published 2014-03-03. Last modified 2026-06-16.