First published: Sat Nov 17 2012(Updated: )
Cross-site scripting (XSS) vulnerability in wp-integrator.php in the WordPress Integrator module 1.32 for WordPress allows remote attackers to inject arbitrary web script or HTML via the redirect_to parameter to wp-login.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Wordpress Integrator Project Wordpress Integrator | =1.32 | |
WordPress |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-5913 is classified as a medium severity cross-site scripting (XSS) vulnerability.
To fix CVE-2012-5913, update the WordPress Integrator module to a version higher than 1.32.
CVE-2012-5913 allows remote attackers to inject arbitrary web scripts or HTML, potentially leading to data theft or user impersonation.
Users of WordPress using the Integrator module version 1.32 are vulnerable to CVE-2012-5913.
In CVE-2012-5913, the redirect_to parameter is exploited by attackers to inject malicious scripts during the login process to wp-login.php.