CVE-2012-5325

Shortcode Redirect <1.0.01 - XSS

Title source: llm

Description

Multiple cross-site scripting (XSS) vulnerabilities in the scr_do_redirect function in scr.php in the Shortcode Redirect plugin 1.0.01 and earlier for WordPress allow remote authenticated users with certain permissions to inject arbitrary web script or HTML via the (1) url or (2) sec attributes in a redirect tag.

Scores

EPSS 0.0011
EPSS Percentile 29.2%

Classification

CWE
CWE-79
Status published

Affected Products (3)

cartpauj/shortcode-redirect < 1.0.01
cartpauj/shortcode-redirect
n/a/n/a

Timeline

Published Oct 08, 2012
Tracked Since Feb 18, 2026