VulnerabilityModified
CVE-2012-4226
Multiple cross-site scripting (XSS) vulnerabilities in Quick Post Widget plugin 1.9.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) Title, (2) Content, or (3) New category field to wordpress/ or (4) query string…
MEDIUM 4.3EPSS 2.04%
Does this matter?
Lower severity and a low EPSS score (2.04%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Quick Post Widget plugin 1.9.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) Title, (2) Content, or (3) New category field to wordpress/ or (4) query string to wordpress/.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 2.04% probability · 80th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- qpw.famvanakkeren/quick post widget
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2012-08/0067.htmlExploit
- http://packetstormsecurity.com/files/115463/WordPress-Quick-Post-Widget-1.9.1-Cross-Site-Scripting.htmlExploit
- http://www.darksecurity.de/advisories/2012/SSCHADV2012-016.txtExploit
- http://www.securityfocus.com/bid/54311
- https://exchange.xforce.ibmcloud.com/vulnerabilities/77731
- http://archives.neohapsis.com/archives/bugtraq/2012-08/0067.htmlExploit
- http://packetstormsecurity.com/files/115463/WordPress-Quick-Post-Widget-1.9.1-Cross-Site-Scripting.htmlExploit
- http://www.darksecurity.de/advisories/2012/SSCHADV2012-016.txtExploit
- http://www.securityfocus.com/bid/54311
- https://exchange.xforce.ibmcloud.com/vulnerabilities/77731
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.