PrettyPhoto Library (Multiple Plugins and Themes) <= 3.1.4 - DOM Cross-Site Scripting

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE CVE-2013-6837
CVSS Medium (6.1)
Publicly Published August 1, 2014
Last Updated January 22, 2024
Researcher Anant Shrivastava (anantshri), PeruCrack
Description

Cross-site scripting (XSS) vulnerability in the setTimeout function in js/jquery.prettyPhoto.js in prettyPhoto 3.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted PATH_INTO to the default URI.

References

34 affected software package

Software Type Plugin
Software Slug random-image-gallery-with-pretty-photo-zoom (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 7.5
Patched Version
  • 7.5
Software Type Plugin
Software Slug mytreasures (view on wordpress.org)
Patched? No
Affected Version
  • <= *
Patched Version
Software Type Plugin
Software Slug wp-business-directory (view on wordpress.org)
Patched? No
Affected Version
  • <= *
Patched Version
Software Type Plugin
Software Slug responsive-lightbox (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.4.12
Patched Version
  • 1.4.12
Software Type Plugin
Software Slug s2member-secure-file-browser (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 0.4.17
Patched Version
  • 0.4.17
Software Type Plugin
Software Slug tallykit (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 5.5
Patched Version
  • 5.5
Software Type Plugin
Software Slug wp-video-lightbox (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.7.5
Patched Version
  • 1.7.5
Software Type Plugin
Software Slug alpine-photo-tile-for-instagram (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.2.7.5
Patched Version
  • 1.2.7.5
Software Type Plugin
Software Slug ehive-account-details (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 2.1.3
Patched Version
  • 2.1.3
Software Type Plugin
Software Slug wp-easy-gallery (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 4.1.1
Patched Version
  • 4.1.1
Software Type Plugin
Software Slug fancyflickr (view on wordpress.org)
Patched? No
Affected Version
  • <= *
Patched Version
Software Type Plugin
Software Slug gallery-bank (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 3.0.229
Patched Version
  • 3.0.229
Software Type Plugin
Software Slug reflex-gallery (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 3.1.5
Patched Version
  • 3.1.5
Software Type Plugin
Software Slug matrix-image-gallery (view on wordpress.org)
Patched? No
Affected Version
  • <= *
Patched Version
Software Type Plugin
Software Slug izeechat (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.1
Patched Version
  • 1.1
Software Type Plugin
Software Slug dp-maintenance-mode-lite (view on wordpress.org)
Patched? No
Affected Version
  • <= *
Patched Version
Software Type Plugin
Software Slug wp-portfolio-gallery (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.2.0
Patched Version
  • 1.2.0
Software Type Plugin
Software Slug ticket-manager (view on wordpress.org)
Patched? No
Affected Version
  • <= *
Patched Version
Software Type Plugin
Software Slug lb-tube-video (view on wordpress.org)
Patched? No
Affected Version
  • <= *
Patched Version
Software Type Plugin
Software Slug ehive-object-details (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 2.1.7
Patched Version
  • 2.1.7
Software Type Plugin
Software Slug onclick-show-popup (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 6.6
Patched Version
  • 6.6
Software Type Plugin
Software Slug jcwp-youtube-channel-embed (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 2.0.0
Patched Version
  • 2.0.0
Software Type Plugin
Software Slug foxyshop (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 4.6.1
Patched Version
  • 4.6.1
Software Type Plugin
Software Slug contact-bank (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 2.0.227
Patched Version
  • 2.0.227
Software Type Plugin
Software Slug image-slider-widget (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.1.7
Patched Version
  • 1.1.7
Software Type Plugin
Software Slug images-lazyload-and-slideshow (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 3.3
Patched Version
  • 3.3
Software Type Plugin
Software Slug wppizza (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 2.11.8.18
Patched Version
  • 2.11.8.18
Software Type Plugin
Software Slug responsive-category-slider (view on wordpress.org)
Patched? No
Affected Version
  • <= *
Patched Version
Software Type Plugin
Software Slug myblogu (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 0.0.8
Patched Version
  • 0.0.8
Software Type Plugin
Software Slug trexanh-property (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 0.1
Patched Version
  • 0.2
Software Type Plugin
Software Slug embedplus-for-wordpress (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 5.4
Patched Version
  • 5.4
Software Type Plugin
Software Slug webrotate-360-product-viewer (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 2.5.2
Patched Version
  • 2.5.2
Software Type Plugin
Software Slug wp-instagram-bank (view on wordpress.org)
Patched? No
Affected Version
  • <= *
Patched Version
Software Type Plugin
Software Slug mklasens-photobox (view on wordpress.org)
Patched? No
Affected Version
  • <= *
Patched Version
This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.
License: Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy. License Detail.