4.3
CVSSv2

CVE-2012-2580

Published: 20/06/2014 Updated: 10/01/2020
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the Postie plugin 1.4.3, and possibly prior to 1.5.15, for WordPress allows remote malicious users to inject arbitrary web script or HTML via the From field of an email.

Vulnerable Product Search on Vulmon Subscribe to Product

postieplugin postie

postieplugin postie 1.4.3

Exploits

#!/usr/bin/python ''' Author: loneferret of Offensive Security Product: Postie Version: 143 Software Download: wordpressorg/extend/plugins/postie/ Timeline: 29 May 2012: Vulnerability reported to CERT 30 May 2012: Response received from CERT with disclosure date set to 20 Jul 2012 23 Jul 2012: Update received from CERT Vendor was advi ...