CVE-2012-2401

Description

Plupload before 1.5.4, as used in wp-includes/js/plupload/ in WordPress before 3.3.2 and other products, enables scripting regardless of the domain from which the SWF content was loaded, which allows remote attackers to bypass the Same Origin Policy via crafted content.

Risk Information

Base Score
7.1
MODERATE
Vector
AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N
EPSS Score
Exploitation Probability
1.038

Associated Vulnerability

VulnerabilityOS Platform
Update wordpress 3.3.1 to latest versionWindows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234