CVE-2013-2202

WordPress < 3.5.2 - XML External Entity Injection via oEmbed Provider Response

Title source: llm
STIX 2.1

Description

WordPress before 3.5.2 allows remote attackers to read arbitrary files via an oEmbed XML provider response containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

References (4)

Core 4
Core References
Vendor Advisory x_refsource_confirm
http://wordpress.org/news/2013/06/wordpress-3-5-2/
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2013/dsa-2718
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=976784
Product x_refsource_confirm
http://codex.wordpress.org/Version_3.5.2

Scores

EPSS 0.0136
EPSS Percentile 80.4%

Details

CWE
CWE-200
Status published
Products (49)
wordpress/wordpress 0.71
wordpress/wordpress 1.0
wordpress/wordpress 1.0.1
wordpress/wordpress 1.0.2
wordpress/wordpress 1.1.1
wordpress/wordpress 1.2
wordpress/wordpress 1.2.1
wordpress/wordpress 1.2.2
wordpress/wordpress 1.2.3
wordpress/wordpress 1.2.4
... and 39 more
Published Jul 08, 2013
Tracked Since Feb 18, 2026