CVE-2012-2572
ThreeWP Email Reflector <1.16 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in the ThreeWP Email Reflector plugin before 1.16 for WordPress allows remote attackers to inject arbitrary web script or HTML via the Subject of an email.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by loneferret · pythonwebappsphp
https://www.exploit-db.com/exploits/20365
References (5)
Scores
EPSS
0.0163
EPSS Percentile
81.7%
Details
CWE
CWE-79
Status
published
Products (17)
mindreantre/threewp_email_reflector
< 1.15
mindreantre/threewp_email_reflector
mindreantre/threewp_email_reflector
mindreantre/threewp_email_reflector
mindreantre/threewp_email_reflector
mindreantre/threewp_email_reflector
mindreantre/threewp_email_reflector
mindreantre/threewp_email_reflector
mindreantre/threewp_email_reflector
mindreantre/threewp_email_reflector
... and 7 more
Published
Jun 19, 2014
Tracked Since
Feb 18, 2026