CVE-2012-2580

Postie 1.4.3-1.5.15 - XSS

Title source: llm

Description

Cross-site scripting (XSS) vulnerability in the Postie plugin 1.4.3, and possibly before 1.5.15, for WordPress allows remote attackers to inject arbitrary web script or HTML via the From field of an email.

Exploits (1)

exploitdb WORKING POC VERIFIED
by loneferret · pythonwebappsphp
https://www.exploit-db.com/exploits/20360

Scores

EPSS 0.0161
EPSS Percentile 81.6%

Details

CWE
CWE-79
Status published
Products (3)
postieplugin/postie < 1.5.14
postieplugin/postie
n/a/n/a
Published Jun 20, 2014
Tracked Since Feb 18, 2026