CVE-2012-2572

ThreeWP Email Reflector <1.16 - XSS

Title source: llm

Description

Cross-site scripting (XSS) vulnerability in the ThreeWP Email Reflector plugin before 1.16 for WordPress allows remote attackers to inject arbitrary web script or HTML via the Subject of an email.

Exploits (1)

exploitdb WORKING POC VERIFIED
by loneferret · pythonwebappsphp
https://www.exploit-db.com/exploits/20365

Scores

EPSS 0.0163
EPSS Percentile 81.7%

Details

CWE
CWE-79
Status published
Products (17)
mindreantre/threewp_email_reflector < 1.15
mindreantre/threewp_email_reflector
mindreantre/threewp_email_reflector
mindreantre/threewp_email_reflector
mindreantre/threewp_email_reflector
mindreantre/threewp_email_reflector
mindreantre/threewp_email_reflector
mindreantre/threewp_email_reflector
mindreantre/threewp_email_reflector
mindreantre/threewp_email_reflector
... and 7 more
Published Jun 19, 2014
Tracked Since Feb 18, 2026