CVE-2012-2401: Medium severity plupload vulnerability
Plupload before 1.5.4, as used in wp-includes/js/plupload/ in WordPress before 3.3.2 and other products, enables scripting regardless of the domain from which the SWF content was loaded, which allows remote attackers to bypass the Same Origin Policy via crafted content.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2401?
CVE-2012-2401 has been classified as a medium severity vulnerability due to its potential impact on the Same Origin Policy.
How do I fix CVE-2012-2401?
To fix CVE-2012-2401, update Plupload to version 1.5.4 or later, or use WordPress version 3.3.2 or later.
What systems are affected by CVE-2012-2401?
CVE-2012-2401 affects all versions of Plupload before 1.5.4 and WordPress versions prior to 3.3.2.
What does CVE-2012-2401 allow attackers to do?
CVE-2012-2401 allows remote attackers to bypass the Same Origin Policy through crafted SWF content.
Is CVE-2012-2401 still a concern for current WordPress installations?
CVE-2012-2401 is not a concern for current WordPress installations if they are updated to the latest versions.