VDB
CVE-2012-2404
CVE-2012-2404
PUBLISHED
CVSS 4.300000190734863 MEDIUM
wp-comments-post.php in WordPress before 3.3.2 supports offsite redirects, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.
EPSS 2.33% · 85.1th percentile
Risk Scores
CVSS 2.0
4.300000190734863
EPSS Score
2.33%
85.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| wordpress | wordpress | 0, 1.0, 1.0.1 |
Timeline
- Apr 21, 2012 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Apr 2, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Sep 7, 2023 EPSS Score
References
- 81464 vdb
- 49138 third-party-advisory
- 48957 third-party-advisory
- wordpress-wpcommentspostphp-xss(75202) vdb
- DSA-2470 vendor-advisory
- 53192 vdb
- http://wordpress.org/news/2012/04/wordpress-3-3-2/ url
- wordpress-wpredirect-xss(75092) vdb
- http://core.trac.wordpress.org/changeset/20486/branches/3.3/wp-comments-post.php url
- https://nvd.nist.gov/vuln/detail/CVE-2012-2404 advisory
- http://wordpress.org/news/2012/04/wordpress-3-3-2 url