Multiple cross-site scripting vulnerabilities in views/notify.php in the Uploader plugin 1.0.4 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) notify or (2) blog parameter.
id: CVE-2013-2287
info:
name: WordPress Plugin Uploader 1.0.4 - Cross-Site Scripting
author: da
...