4.3
CVSSv2

CVE-2013-0236

Published: 08/07/2013 Updated: 21/11/2024

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in WordPress prior to 3.5.1 allow remote malicious users to inject arbitrary web script or HTML via vectors involving (1) gallery shortcodes or (2) the content of a post.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

wordpress wordpress

wordpress wordpress 0.71

wordpress wordpress 1.0

wordpress wordpress 1.0.1

wordpress wordpress 1.0.2

wordpress wordpress 1.1.1

wordpress wordpress 1.2

wordpress wordpress 1.2.1

wordpress wordpress 1.2.2

wordpress wordpress 1.2.3

wordpress wordpress 1.2.4

wordpress wordpress 1.2.5

wordpress wordpress 1.3

wordpress wordpress 1.3.2

wordpress wordpress 1.3.3

wordpress wordpress 1.5

wordpress wordpress 1.5.1

wordpress wordpress 1.5.1.1

wordpress wordpress 1.5.1.2

wordpress wordpress 1.5.1.3

wordpress wordpress 1.5.2

wordpress wordpress 1.6.2

wordpress wordpress 2.0

wordpress wordpress 2.0.1

wordpress wordpress 2.0.2

wordpress wordpress 2.0.4

wordpress wordpress 2.0.5

wordpress wordpress 2.0.6

wordpress wordpress 2.0.7

wordpress wordpress 2.0.8

wordpress wordpress 2.0.9

wordpress wordpress 2.0.10

wordpress wordpress 2.0.11

wordpress wordpress 2.1

wordpress wordpress 2.1.1

wordpress wordpress 2.1.2

wordpress wordpress 2.1.3

wordpress wordpress 2.2

wordpress wordpress 2.2.1

wordpress wordpress 2.2.2

wordpress wordpress 2.2.3

wordpress wordpress 2.3

wordpress wordpress 2.3.1

wordpress wordpress 2.3.2

wordpress wordpress 2.3.3

wordpress wordpress 2.5

wordpress wordpress 2.5.1

wordpress wordpress 2.6

wordpress wordpress 2.6.1

wordpress wordpress 2.6.2

wordpress wordpress 2.6.3

wordpress wordpress 2.6.5

wordpress wordpress 2.7

wordpress wordpress 2.7.1

wordpress wordpress 2.8

wordpress wordpress 2.8.1

wordpress wordpress 2.8.2

wordpress wordpress 2.8.3

wordpress wordpress 2.8.4

wordpress wordpress 2.8.5

wordpress wordpress 2.8.5.1

wordpress wordpress 2.8.5.2

wordpress wordpress 2.8.6

wordpress wordpress 2.9

wordpress wordpress 2.9.1

wordpress wordpress 2.9.1.1

wordpress wordpress 2.9.2

wordpress wordpress 3.3

wordpress wordpress 3.3.1

wordpress wordpress 3.3.2

wordpress wordpress 3.3.3

wordpress wordpress 3.4.0

wordpress wordpress 3.4.1

wordpress wordpress 3.4.2

Vendor Advisories

Debian Bug report logs - #698927 wordpress: CVE-2013-0236: XSS via shortcodes and post content fixed in 351 Package: wordpress; Maintainer for wordpress is Craig Small <csmall@debianorg>; Source for wordpress is src:wordpress (PTS, buildd, popcon) Reported by: Henri Salo <henri@nervfi> Date: Fri, 25 Jan 2013 09:3 ...