CVE-2012-6692: XSS
Cross-site scripting (XSS) vulnerability in js/wp-seo-metabox.js in the WordPress SEO by Yoast plugin before 2.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the posttitle parameter to wp-admin/post-new.php, which is not properly handled in the snippet preview functionality.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2012-6692?
CVE-2012-6692 is considered a medium severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2012-6692?
To fix CVE-2012-6692, update the WordPress SEO by Yoast plugin to version 2.2 or later.
What types of attacks can be performed using CVE-2012-6692?
CVE-2012-6692 allows attackers to perform cross-site scripting attacks by injecting arbitrary scripts through the post_title parameter.
Who is affected by CVE-2012-6692?
CVE-2012-6692 affects users of the WordPress SEO by Yoast plugin prior to version 2.2.
Is CVE-2012-6692 still exploitable in recent versions of the plugin?
No, CVE-2012-6692 is no longer exploitable in versions of the WordPress SEO by Yoast plugin that are updated to 2.2 or later.