CVE-2013-0236
EPSS 0.42%Published: 7/8/2013Modified: 5/27/2026
Description
Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.5.1 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) gallery shortcodes or (2) the content of a post.
Affected packages (1)
- Debian/wordpressfrom 0, < 3.5.1+dfsg-1