CVE-2011-5207
Thecartpress < 1.1.6 - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in admin/OptionsPostsList.php in the TheCartPress plugin for WordPress before 1.1.6 before 2011-12-31 allows remote attackers to inject arbitrary web script or HTML via the tcp_name_post_XXXXX parameter.
Exploits (1)
References (5)
Scores
EPSS
0.0422
EPSS Percentile
88.6%
Classification
CWE
CWE-79
Status
published
Affected Products (18)
thecartpress/thecartpress
thecartpress/thecartpress
< 1.1.6
thecartpress/thecartpress
thecartpress/thecartpress
thecartpress/thecartpress
thecartpress/thecartpress
thecartpress/thecartpress
thecartpress/thecartpress
thecartpress/thecartpress
thecartpress/thecartpress
thecartpress/thecartpress
thecartpress/thecartpress
thecartpress/thecartpress
thecartpress/thecartpress
thecartpress/thecartpress
... and 3 more
Timeline
Published
Oct 04, 2012
Tracked Since
Feb 18, 2026