Cross-Site Scripting Vulnerabilities in Pay With Tweet Plugin by WordPress
CVE-2012-5349
Currently unrated
What is CVE-2012-5349?
Multiple cross-site scripting vulnerabilities exist within the Pay With Tweet plugin for WordPress, particularly in the pay.php file. These vulnerabilities allow remote attackers to inject arbitrary web scripts or HTML code through the 'link', 'title', or 'dl' parameters. Exploitation of these weaknesses can lead to unauthorized actions performed on behalf of users, potentially compromising sensitive user data or session information.