CVE-2012-1068

WP-RecentComments <2.0.7 - XSS

Title source: llm

Description

Cross-site scripting (XSS) vulnerability in the rc_ajax function in core.php in the WP-RecentComments plugin before 2.0.7 for WordPress allows remote attackers to inject arbitrary web script or HTML via the page parameter, related to AJAX paging.

Scores

EPSS 0.0027
EPSS Percentile 50.5%

Classification

CWE
CWE-79
Status published

Affected Products (12)

mg12/wp-recentcomments < 2.0.7
mg12/wp-recentcomments
mg12/wp-recentcomments
mg12/wp-recentcomments
mg12/wp-recentcomments
mg12/wp-recentcomments
mg12/wp-recentcomments
mg12/wp-recentcomments
mg12/wp-recentcomments
mg12/wp-recentcomments
mg12/wp-recentcomments
n/a/n/a

Timeline

Published Feb 14, 2012
Tracked Since Feb 18, 2026