VDB
DEBIAN-CVE-2013-2201
DEBIAN-CVE-2013-2201
PUBLISHED
CVSS 9.300000190734863 CRITICAL
Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.5.2 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) uploads of media files, (2) editing of media files, (3) installation of plugins, (4) updates to plugins, (5) installation of themes, or (6) updates to themes.
Risk Scores
CVSS 4.0
9.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian:14 | wordpress | 0 |
| Debian:12 | wordpress | 0, 0, 0 |
| Debian:11 | wordpress | 0, 0, 0 |
| Debian:13 | wordpress | 0, 0, 0 |
Timeline
- Jul 8, 2013 CVE Published
- May 7, 2026 CVE Updated