CVE-2011-3841
WP Symposium <11.12.08 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in uploadify/get_profile_avatar.php in the WP Symposium plugin before 11.12.08 for WordPress allows remote attackers to inject arbitrary web script or HTML via the uid parameter.
References (5)
Scores
EPSS
0.0047
EPSS Percentile
64.2%
Classification
CWE
CWE-79
Status
published
Affected Products (2)
wpsymposiumpro/wp_symposium
< 11.12.08
n/a/n/a
Timeline
Published
Dec 27, 2011
Tracked Since
Feb 18, 2026