CVE-2012-2580
Postie < 1.5.15 - Cross-Site Scripting via Email From Field
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2012-2580. PoCs published by loneferret.
AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in Postie plugin for WordPress by sending a malicious email with an XSS payload in the 'From' field. The payload executes when the email is processed by the plugin.
Description
Cross-site scripting (XSS) vulnerability in the Postie plugin 1.4.3, and possibly before 1.5.15, for WordPress allows remote attackers to inject arbitrary web script or HTML via the From field of an email.
Exploits (1)
This exploit demonstrates a stored XSS vulnerability in Postie plugin for WordPress by sending a malicious email with an XSS payload in the 'From' field. The payload executes when the email is processed by the plugin.