CVE-2013-3487: Ait-Pro Bulletproof-Security

Medium severity, CVSS 4.3. EPSS: 2.3% chance of exploitation in the next 30 days.

Multiple cross-site scripting (XSS) vulnerabilities in the security log in the BulletProof Security plugin before .49 for WordPress allow remote attackers to inject arbitrary web script or HTML via unspecified HTML header fields to (1) 400.php, (2) 403.php, or (3) 403.php.

Affected products

  • Ait-Pro Bulletproof-Security: up to and including .48.9; version .45.4 only; version .45.5 only; version .45.6 only; version .45.7 only; version .45.8 only; …

Published 2014-03-03. Last modified 2026-06-16.