CVE-2012-0287
WordPress <3.3.1 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in wp-comments-post.php in WordPress 3.3.x before 3.3.1, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via the query string in a POST operation that is not properly handled by the "Duplicate comment detected" feature.
References (4)
Scores
EPSS
0.0060
EPSS Percentile
69.2%
Classification
CWE
CWE-79
Status
published
Affected Products (2)
wordpress/wordpress
n/a/n/a
Timeline
Published
Jan 06, 2012
Tracked Since
Feb 18, 2026