peter bassill · operator
$ cve CVE-2012-0782 JSON

CVE-2012-0782 EXPLOIT

4.3
MEDIUM · CVSS 2.0 · EPSS 3.5% (pctl 89)

Patch early

A public exploit exists.

Description

Multiple cross-site scripting (XSS) vulnerabilities in wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) dbhost, (2) dbname, or (3) uname parameter. NOTE: the vendor disputes the significance of this issue; also, it is unclear whether this specific XSS scenario has security relevance

Scoring

CVSS4.3 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS3.55% — more likely to be exploited than 89% of all CVEs
WeaknessCWE-79
On CISA KEVno
Public exploityes
Published2012-01-30
Last modified2026-06-16

Affected (1)

VendorProduct
wordpresswordpress

Public exploits

SourceTitleDate
exploit-dbWordPress Core 3.3.1 - Multiple Vulnerabilities2012-01-25

References

→ the Explorer  ·  watch your stack  ·  NVD