CVE-2012-2920
WordPress User Photo <0.9.5.2 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in the userphoto_options_page function in user-photo.php in the User Photo plugin before 0.9.5.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to wp-admin/options-general.php. NOTE: some of these details are obtained from third party information.
References (6)
Scores
EPSS
0.0027
EPSS Percentile
50.5%
Classification
CWE
CWE-79
Status
published
Affected Products (20)
user_photo/user_photo
< 0.9.5
user_photo/user_photo
user_photo/user_photo
user_photo/user_photo
user_photo/user_photo
user_photo/user_photo
user_photo/user_photo
user_photo/user_photo
user_photo/user_photo
user_photo/user_photo
user_photo/user_photo
user_photo/user_photo
user_photo/user_photo
user_photo/user_photo
user_photo/user_photo
... and 5 more
Timeline
Published
May 21, 2012
Tracked Since
Feb 18, 2026