47475Third-party advisory
http://secunia.com/advisories/47475 CVE-2012-5349
WordPress Plugin Pay with Tweet 1.1 - Multiple Vulnerabilities
Record summary
CVE-2012-5349 has a selected CVSS score of 2.6; EIP currently links 1 catalogued exploit.
Description
Multiple cross-site scripting (XSS) vulnerabilities in pay.php in the Pay With Tweet plugin before 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) link, (2) title, or (3) dl parameter.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBWordPress Plugin Pay with Tweet 1.1 - Multiple VulnerabilitiesExploitDB exploitby Gianluca BrindisiNot analyzed1 file
References
7wordpress.orgConfirmation
http://wordpress.org/extend/plugins/pay-with-tweet/changelog 18330exploit
http://www.exploit-db.com/exploits/18330 78205vdb entry
http://www.osvdb.org/78205 51308vdb entry
http://www.securityfocus.com/bid/51308 paywithtweet-pay-xss(72166)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/72166 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2012-5349