CVE-2012-4264

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
13/08/2012
Last modified:
11/04/2025

Description

Multiple cross-site scripting (XSS) vulnerabilities in the Better WP Security (better_wp_security) plugin before 3.2.5 for WordPress allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "server variables," a different vulnerability than CVE-2012-4263.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:bit51:better-wp-security:*:*:*:*:*:*:*:* 3.2.4 (including)
cpe:2.3:a:bit51:better-wp-security:-:alpha1:*:*:*:*:*:*
cpe:2.3:a:bit51:better-wp-security:-:alpha10:*:*:*:*:*:*
cpe:2.3:a:bit51:better-wp-security:-:alpha11:*:*:*:*:*:*
cpe:2.3:a:bit51:better-wp-security:-:alpha2:*:*:*:*:*:*
cpe:2.3:a:bit51:better-wp-security:-:alpha3:*:*:*:*:*:*
cpe:2.3:a:bit51:better-wp-security:-:alpha4:*:*:*:*:*:*
cpe:2.3:a:bit51:better-wp-security:-:alpha5:*:*:*:*:*:*
cpe:2.3:a:bit51:better-wp-security:-:alpha6:*:*:*:*:*:*
cpe:2.3:a:bit51:better-wp-security:-:alpha7:*:*:*:*:*:*
cpe:2.3:a:bit51:better-wp-security:-:alpha8:*:*:*:*:*:*
cpe:2.3:a:bit51:better-wp-security:-:alpha9:*:*:*:*:*:*
cpe:2.3:a:bit51:better-wp-security:0.1:alpha:*:*:*:*:*:*
cpe:2.3:a:bit51:better-wp-security:0.1:beta:*:*:*:*:*:*
cpe:2.3:a:bit51:better-wp-security:0.2:beta:*:*:*:*:*:*