CVE-2012-2580
Postie 1.4.3-1.5.15 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in the Postie plugin 1.4.3, and possibly before 1.5.15, for WordPress allows remote attackers to inject arbitrary web script or HTML via the From field of an email.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by loneferret · pythonwebappsphp
https://www.exploit-db.com/exploits/20360
References (5)
Scores
EPSS
0.0161
EPSS Percentile
81.6%
Details
CWE
CWE-79
Status
published
Products (3)
postieplugin/postie
< 1.5.14
postieplugin/postie
n/a/n/a
Published
Jun 20, 2014
Tracked Since
Feb 18, 2026