CVE-2012-2913
Leaflet plugin <0.0.1 - XSS
Title source: llmDescription
Multiple cross-site scripting (XSS) vulnerabilities in the Leaflet plugin 0.0.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via the id parameter to (1) leaflet_layer.php or (2) leaflet_marker.php, as reachable through wp-admin/admin.php.
Exploits (2)
exploitdb
WRITEUP
VERIFIED
by Heine Pedersen · textwebappsphp
https://www.exploit-db.com/exploits/37192
exploitdb
WORKING POC
VERIFIED
by Heine Pedersen · textwebappsphp
https://www.exploit-db.com/exploits/37191
Scores
EPSS
0.0072
EPSS Percentile
72.2%
Classification
CWE
CWE-79
Status
published
Affected Products (2)
mapsmarker/leaflet_maps_marker_plugin
n/a/n/a
Timeline
Published
May 21, 2012
Tracked Since
Feb 18, 2026