CVE-2013-0236

EPSS 0.42%
Published: 7/8/2013Modified: 5/27/2026

Description

Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.5.1 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) gallery shortcodes or (2) the content of a post.

Affected packages (1)

References (1)