Cross-site scripting in WordPress - CVE-2012-2403
Published: April 22, 2012 / Updated: November 1, 2020
WordPress
Detailed vulnerability description
The vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data when processing data passed via unspecified vectors. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
How to mitigate CVE-2012-2403
Sources
- http://core.trac.wordpress.org/changeset/20493/branches/3.3/wp-includes/capabilities.php
- http://core.trac.wordpress.org/changeset/20493/branches/3.3/wp-includes/formatting.php
- http://osvdb.org/81463
- http://secunia.com/advisories/48957
- http://secunia.com/advisories/49138
- http://wordpress.org/news/2012/04/wordpress-3-3-2/
- http://www.debian.org/security/2012/dsa-2470
- http://www.securityfocus.com/bid/53192
- https://exchange.xforce.ibmcloud.com/vulnerabilities/75093
- https://exchange.xforce.ibmcloud.com/vulnerabilities/75206