Published: 08/07/2013 Updated: 08/07/2013
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in WordPress prior to 3.5.1 allow remote malicious users to inject arbitrary web script or HTML via vectors involving (1) gallery shortcodes or (2) the content of a post.

Vendor Advisories

Debian Bug report logs - #698927 wordpress: CVE-2013-0236: XSS via shortcodes and post content fixed in 351 Package: wordpress; Maintainer for wordpress is Craig Small <csmall@debianorg>; Source for wordpress is src:wordpress (PTS, buildd, popcon) Reported by: Henri Salo <henri@nervfi> Date: Fri, 25 Jan 2013 09:3 ...