CVE-2012-2401
Plupload before 1.5.4, as used in wp-includes/js/plupload/ in WordPress before 3.3.2 and other products, enables scripting regardless of the domain from which the SWF content was loaded, which allows remote attackers to bypass the Same Origin Policy via…
Does this matter?
Lower severity and a low EPSS score (3.38%). Track it; it rarely justifies an emergency change on its own.
Description
Plupload before 1.5.4, as used in wp-includes/js/plupload/ in WordPress before 3.3.2 and other products, enables scripting regardless of the domain from which the SWF content was loaded, which allows remote attackers to bypass the Same Origin Policy via crafted content.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 3.38% probability · 88th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- moxiecode/plupload · wordpress/wordpress
- Source
- cve@mitre.org
References
- http://core.trac.wordpress.org/browser/branches/3.3/wp-includes/js/plupload/changelog.txt?rev=20487
- http://core.trac.wordpress.org/browser/branches/3.3/wp-includes/js/plupload?rev=20487
- http://osvdb.org/81461
- http://secunia.com/advisories/49138Vendor Advisory
- http://wordpress.org/news/2012/04/wordpress-3-3-2/Patch, Vendor Advisory
- http://www.debian.org/security/2012/dsa-2470
- http://www.plupload.com/punbb/viewtopic.php?id=1685
- http://www.securityfocus.com/bid/53192
- https://exchange.xforce.ibmcloud.com/vulnerabilities/75208
- https://nealpoole.com/blog/2012/05/xss-and-csrf-via-swf-applets-swfupload-plupload/
- http://core.trac.wordpress.org/browser/branches/3.3/wp-includes/js/plupload/changelog.txt?rev=20487
- http://core.trac.wordpress.org/browser/branches/3.3/wp-includes/js/plupload?rev=20487
- http://osvdb.org/81461
- http://secunia.com/advisories/49138Vendor Advisory
- http://wordpress.org/news/2012/04/wordpress-3-3-2/Patch, Vendor Advisory
- http://www.debian.org/security/2012/dsa-2470
- http://www.plupload.com/punbb/viewtopic.php?id=1685
- http://www.securityfocus.com/bid/53192
- https://exchange.xforce.ibmcloud.com/vulnerabilities/75208
- https://nealpoole.com/blog/2012/05/xss-and-csrf-via-swf-applets-swfupload-plupload/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.