CVE-2013-2501
Cross-site scripting (XSS) vulnerability in the Terillion Reviews plugin before 1.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the ProfileId field.
Date published : 2013-03-22
http://www.securityfocus.com/bid/58415
http://archives.neohapsis.com/archives/bugtraq/2013-03/0055.html