CVE-2013-2201: XSS
Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.5.2 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) uploads of media files, (2) editing of media files, (3) installation of plugins, (4) updates to plugins, (5) installation of themes, or (6) updates to themes.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2201?
CVE-2013-2201 is classified as a moderate to high severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2013-2201?
To fix CVE-2013-2201, upgrade your WordPress installation to version 3.5.2 or later.
What types of attacks are possible with CVE-2013-2201?
CVE-2013-2201 allows attackers to perform cross-site scripting (XSS) attacks, potentially leading to unauthorized actions on behalf of users.
Which versions of WordPress are affected by CVE-2013-2201?
CVE-2013-2201 affects all versions of WordPress prior to 3.5.2.
What are the common exploitation vectors for CVE-2013-2201?
Common exploitation vectors for CVE-2013-2201 involve media file uploads, media file editing, and insecure plugin and theme installations.