Description
Cross-site scripting (XSS) vulnerability in index.php in the WP-FaceThumb plugin 0.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the pagination_wp_facethumb parameter.
Exploits (1)
Nuclei Templates (1)
WP-FaceThumb 0.1 - Cross-Site Scripting
MEDIUMby daffainfo
References (6)
Core 6
Core References
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/49143
Exploit x_refsource_misc
http://packetstormsecurity.org/files/112658/WordPress-WP-FaceThumb-Gallery-0.1-Cross-Site-Scripting.html
Exploit vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/53497
Product x_refsource_misc
http://wordpress.org/support/topic/plugin-wp-facethumb-reflected-xss-vulnerability-cwe-79
Mailing List mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2012/05/15/12
Mailing List mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2012/05/16/1
Scores
EPSS
0.0371
EPSS Percentile
88.1%
Details
CWE
CWE-79
Status
published
Products (1)
mnt-tech/wp-facethumb
0.1
Published
Aug 13, 2012
Tracked Since
Feb 18, 2026