CVE-2012-4263

UnknownEPSS 2.07%

Last modified

CVE-2012-4263 is a vulnerability of currently unknown severity. Cross-site scripting (XSS) vulnerability in inc/admin/content.php in the Better WP Security (better_wp_security) plugin before 3.2.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the HTTP_USER_AGENT header.. EPSS estimates a 2.07% chance of exploitation in the next 30 days.

Description

Cross-site scripting (XSS) vulnerability in inc/admin/content.php in the Better WP Security (better_wp_security) plugin before 3.2.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the HTTP_USER_AGENT header.

Metrics

EPSS Probability
2.07%

78.9th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
Bit51Better-Wp-Security<= 3.2.4
Bit51Better-Wp-SecurityAll versionsAlpha1
Bit51Better-Wp-Security0.1Alpha
Bit51Better-Wp-Security0.2Beta
Bit51Better-Wp-Security0.3Beta
Bit51Better-Wp-Security0.4Beta
Bit51Better-Wp-Security0.5Beta
Bit51Better-Wp-Security0.6Beta
Bit51Better-Wp-Security0.7Beta
Bit51Better-Wp-Security0.8Beta
Bit51Better-Wp-Security0.9Beta
Bit51Better-Wp-Security0.10Beta
Bit51Better-Wp-Security0.11Beta
Bit51Better-Wp-Security0.13Beta
Bit51Better-Wp-Security0.14Beta
Bit51Better-Wp-Security0.15Beta
Bit51Better-Wp-Security0.16Beta
Bit51Better-Wp-Security1.0
Bit51Better-Wp-Security1.1
Bit51Better-Wp-Security1.2
Bit51Better-Wp-Security1.3
Bit51Better-Wp-Security1.4
Bit51Better-Wp-Security1.5
Bit51Better-Wp-Security1.6
Bit51Better-Wp-Security1.7
Bit51Better-Wp-Security1.8
Bit51Better-Wp-Security1.8.1
Bit51Better-Wp-Security1.9
Bit51Better-Wp-Security2.0
Bit51Better-Wp-Security2.1
Bit51Better-Wp-Security2.2
Bit51Better-Wp-Security2.3
Bit51Better-Wp-Security2.4
Bit51Better-Wp-Security2.5
Bit51Better-Wp-Security2.6
Bit51Better-Wp-Security2.7
Bit51Better-Wp-Security2.8
Bit51Better-Wp-Security2.9
Bit51Better-Wp-Security2.10
Bit51Better-Wp-Security2.11
Bit51Better-Wp-Security2.12
Bit51Better-Wp-Security2.13
Bit51Better-Wp-Security2.14
Bit51Better-Wp-Security2.15
Bit51Better-Wp-Security2.16
Bit51Better-Wp-Security2.17
Bit51Better-Wp-Security2.18
Bit51Better-Wp-Security3.0
Bit51Better-Wp-Security3.0.1
Bit51Better-Wp-Security3.0.2

Showing 50 of 66 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2012-4263?
Cross-site scripting (XSS) vulnerability in inc/admin/content.php in the Better WP Security (better_wp_security) plugin before 3.2.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the HTTP_USER_AGENT header.
How severe is CVE-2012-4263?
Severity scoring for CVE-2012-4263 is pending analysis. The EPSS model estimates a 2.07% probability of exploitation in the next 30 days.
How do I fix CVE-2012-4263?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2012-4263?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST