CVE-2012-1068
WP-RecentComments <2.0.7 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in the rc_ajax function in core.php in the WP-RecentComments plugin before 2.0.7 for WordPress allows remote attackers to inject arbitrary web script or HTML via the page parameter, related to AJAX paging.
References (6)
Scores
EPSS
0.0027
EPSS Percentile
50.5%
Classification
CWE
CWE-79
Status
published
Affected Products (12)
mg12/wp-recentcomments
< 2.0.7
mg12/wp-recentcomments
mg12/wp-recentcomments
mg12/wp-recentcomments
mg12/wp-recentcomments
mg12/wp-recentcomments
mg12/wp-recentcomments
mg12/wp-recentcomments
mg12/wp-recentcomments
mg12/wp-recentcomments
mg12/wp-recentcomments
n/a/n/a
Timeline
Published
Feb 14, 2012
Tracked Since
Feb 18, 2026