Exploitation Summary
EIP tracks 1 public exploit for CVE-2012-2572. PoCs published by loneferret.
AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in ThreeWP Email Reflector plugin for WordPress. It sends an email with a malicious payload in the subject field, which gets reflected in the plugin's interface.
Description
Cross-site scripting (XSS) vulnerability in the ThreeWP Email Reflector plugin before 1.16 for WordPress allows remote attackers to inject arbitrary web script or HTML via the Subject of an email.
Exploits (1)
This exploit demonstrates a stored XSS vulnerability in ThreeWP Email Reflector plugin for WordPress. It sends an email with a malicious payload in the subject field, which gets reflected in the plugin's interface.