CVE-2012-2633

WassUp Plugin < 1.8.3 - Cross-Site Scripting via User-Agent HTTP Header

Title source: llm
STIX 2.1

Description

Cross-site scripting (XSS) vulnerability in wassup.php in the WassUp plugin before 1.8.3.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header.

References (6)

Core 6
Core References
Third Party Advisory third-party-advisory x_refsource_jvndb
http://jvndb.jvn.jp/jvndb/JVNDB-2012-000058
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/82017
Various Sources x_refsource_confirm
http://www.wpwp.org/archives/wassup-1-8-3-1/
Third Party Advisory third-party-advisory x_refsource_jvn
http://jvn.jp/en/jp/JVN15646988/index.html

Scores

EPSS 0.0030
EPSS Percentile 53.0%

Details

CWE
CWE-79
Status published
Products (8)
wordpress/wassup_plugin 1.4
wordpress/wassup_plugin 1.4.3
wordpress/wassup_plugin 1.7.2
wordpress/wassup_plugin 1.7.2.1
wordpress/wassup_plugin 1.8
wordpress/wassup_plugin 1.8.1
wordpress/wassup_plugin 1.8.2
wordpress/wassup_plugin < 1.8.3
Published Jun 15, 2012
Tracked Since Feb 18, 2026