VDB

DEBIAN-CVE-2013-2201

DEBIAN-CVE-2013-2201 PUBLISHED CVSS 9.300000190734863 CRITICAL

Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.5.2 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) uploads of media files, (2) editing of media files, (3) installation of plugins, (4) updates to plugins, (5) installation of themes, or (6) updates to themes.

Risk Scores

CVSS 4.0
9.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Affected Products

VendorProductVersions
Debian:14wordpress0
Debian:12wordpress0, 0, 0
Debian:11wordpress0, 0, 0
Debian:13wordpress0, 0, 0

Timeline

  • Jul 8, 2013 CVE Published
  • May 7, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›