CVE-2013-0236: XSS
From WordPress upstream v3.5.1 advisory [1]: Two instances of cross-site scripting via shortcodes and post content. These issues were discovered by Jon Cave of the WordPress security team.
References: [1] http://wordpress.org/news/2013/01/wordpress-3-5-1/ [2] http://www.openwall.com/lists/oss-security/2013/01/25/7
Other sources
Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.5.1 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) gallery shortcodes or (2) the content of a post.
— MITRE
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0236?
CVE-2013-0236 has been classified as a moderate severity vulnerability due to its cross-site scripting nature.
How do I fix CVE-2013-0236?
To fix CVE-2013-0236, upgrade your WordPress installation to version 3.5.2 or later.
What types of vulnerabilities are associated with CVE-2013-0236?
CVE-2013-0236 is associated with cross-site scripting vulnerabilities that can be exploited through shortcodes and post content.
Which versions of WordPress are affected by CVE-2013-0236?
CVE-2013-0236 affects WordPress versions up to and including 3.5.1.
Who discovered the vulnerability listed as CVE-2013-0236?
CVE-2013-0236 was discovered by Jon Cave of the WordPress security team.