CVE-2012-2579
WP SimpleMail 1.0.6 - XSS
Title source: llmDescription
Multiple cross-site scripting (XSS) vulnerabilities in the WP SimpleMail plugin 1.0.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) To, (2) From, (3) Date, or (4) Subject field of an email.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by loneferret · pythonwebappsphp
https://www.exploit-db.com/exploits/20361
References (5)
Scores
EPSS
0.0161
EPSS Percentile
81.6%
Details
CWE
CWE-79
Status
published
Products (2)
wp_simplemail_project/wp_simplemail
n/a/n/a
Published
Jun 20, 2014
Tracked Since
Feb 18, 2026