5
CVSSv2

CVE-2012-2401

Published: 21/04/2012 Updated: 19/12/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Plupload prior to 1.5.4, as used in wp-includes/js/plupload/ in WordPress prior to 3.3.2 and other products, enables scripting regardless of the domain from which the SWF content was loaded, which allows remote malicious users to bypass the Same Origin Policy via crafted content.

Vulnerable Product Search on Vulmon Subscribe to Product

wordpress wordpress

wordpress wordpress 2.0.9

wordpress wordpress 2.2

wordpress wordpress 2.0

wordpress wordpress 2.3.2

wordpress wordpress 2.0.1

wordpress wordpress 2.0.7

wordpress wordpress 2.1

wordpress wordpress 2.8.1

wordpress wordpress 2.8.2

wordpress wordpress 2.2.3

wordpress wordpress 2.6.2

wordpress wordpress 2.3.1

wordpress wordpress 1.5.1.2

wordpress wordpress 2.0.2

wordpress wordpress 2.0.4

wordpress wordpress 2.7

wordpress wordpress 3.0.3

wordpress wordpress 2.3.3

wordpress wordpress 3.0.5

wordpress wordpress 2.2.2

wordpress wordpress 3.0.1

wordpress wordpress 1.2.2

wordpress wordpress 1.0.2

wordpress wordpress 0.71

wordpress wordpress 1.2.5

wordpress wordpress 2.7.1

wordpress wordpress 3.1.2

wordpress wordpress 1.3

wordpress wordpress 1.3.2

moxiecode plupload 1.4.2

moxiecode plupload 1.4.1

moxiecode plupload 1.4.0

wordpress wordpress 2.8.4

wordpress wordpress 3.0.6

wordpress wordpress 1.5

wordpress wordpress 2.9.2

wordpress wordpress 2.9.1

wordpress wordpress 1.0

wordpress wordpress 1.2.4

wordpress wordpress 3.1.3

wordpress wordpress 2.8.5.1

wordpress wordpress 2.8.5.2

moxiecode plupload 1.5.1

moxiecode plupload 1.5.0

wordpress wordpress 2.0.8

wordpress wordpress 2.8

wordpress wordpress 1.5.1.3

wordpress wordpress 1.5.2

wordpress wordpress 2.0.5

wordpress wordpress 2.0.6

wordpress wordpress 2.8.3

wordpress wordpress 2.8.5

wordpress wordpress 2.8.6

wordpress wordpress 2.6.3

wordpress wordpress 3.1

wordpress wordpress 3.0.2

wordpress wordpress 3.0

wordpress wordpress 2.9

wordpress wordpress 1.2

wordpress wordpress 2.5

wordpress wordpress 1.2.3

wordpress wordpress 2.9.1.1

wordpress wordpress 3.0.4

moxiecode plupload

moxiecode plupload 1.5.2

wordpress wordpress 2.0.11

wordpress wordpress 2.1.3

wordpress wordpress 2.2.1

wordpress wordpress 1.5.1.1

wordpress wordpress 3.3

wordpress wordpress 2.0.10

wordpress wordpress 2.1.1

wordpress wordpress 2.1.2

wordpress wordpress 2.5.1

wordpress wordpress 2.3

wordpress wordpress 2.6.1

wordpress wordpress 2.6

wordpress wordpress 1.5.1

wordpress wordpress 1.2.1

wordpress wordpress 1.0.1

wordpress wordpress 2.6.5

wordpress wordpress 1.1.1

wordpress wordpress 3.1.1

wordpress wordpress 1.3.3

moxiecode plupload 1.4.3

Vendor Advisories

Debian Bug report logs - #713947 wordpress: Multiple security issues Package: wordpress; Maintainer for wordpress is Craig Small <csmall@debianorg>; Source for wordpress is src:wordpress (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Mon, 24 Jun 2013 06:39:02 UTC Severity: grave Tags: ...
Several vulnerabilities were identified in WordPress, a web blogging tool As the CVEs were allocated from releases announcements and specific fixes are usually not identified, it has been decided to upgrade the wordpress package to the latest upstream version instead of backporting the patches This means extra care should be taken when upgrading, ...