CVE-2012-2920

WordPress User Photo <0.9.5.2 - XSS

Title source: llm

Description

Cross-site scripting (XSS) vulnerability in the userphoto_options_page function in user-photo.php in the User Photo plugin before 0.9.5.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to wp-admin/options-general.php. NOTE: some of these details are obtained from third party information.

Scores

EPSS 0.0027
EPSS Percentile 50.5%

Classification

CWE
CWE-79
Status published

Affected Products (20)

user_photo/user_photo < 0.9.5
user_photo/user_photo
user_photo/user_photo
user_photo/user_photo
user_photo/user_photo
user_photo/user_photo
user_photo/user_photo
user_photo/user_photo
user_photo/user_photo
user_photo/user_photo
user_photo/user_photo
user_photo/user_photo
user_photo/user_photo
user_photo/user_photo
user_photo/user_photo
... and 5 more

Timeline

Published May 21, 2012
Tracked Since Feb 18, 2026