Cross-Site Scripting Vulnerabilities in Organizer Plugin for WordPress
CVE-2012-6511

Currently unrated

Key Information:

Vendor
Wordpress
Status
Vendor
CVE Published:
24 January 2013

Summary

The Organizer plugin for WordPress version 1.2.1 contains multiple cross-site scripting (XSS) vulnerabilities that enable remote attackers to inject arbitrary web scripts or HTML code. These vulnerabilities can be exploited via crafted input to the 'delete_id' or 'extension' parameters during an 'Update Setting' action triggered through wp-admin/admin.php. This could lead to unauthorized access and compromise of user interactions on web pages, posing a serious security risk to users of the affected plugin.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.