Cross-Site Scripting Vulnerability in CMS Tree Page View Plugin for WordPress
CVE-2012-1834
Currently unrated
What is CVE-2012-1834?
The CMS Tree Page View plugin for WordPress suffers from a Cross-Site Scripting (XSS) vulnerability due to insufficient validation of user input in the cms_tpv_admin_head function. This vulnerability allows remote attackers to inject arbitrary web scripts or HTML via the 'cms_tpv_view' parameter when accessing wp-admin/options-general.php. If exploited, this could lead to the execution of malicious scripts in the browser of any user accessing the affected administrative features, potentially compromising sensitive information or allowing unauthorized actions.