Description
Multiple cross-site scripting (XSS) vulnerabilities in wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) dbhost, (2) dbname, or (3) uname parameter. NOTE: the vendor disputes the significance of this issue; also, it is unclear whether this specific XSS scenario has security relevance
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-16T23:26:38.397Z
Reserved: 2012-01-18T00:00:00.000Z
Link: CVE-2012-0782
No data.
Status : Modified
Published: 2012-01-30T17:55:00.843
Modified: 2026-04-29T01:13:23.040
Link: CVE-2012-0782
No data.
OpenCVE Enrichment
No data.
Weaknesses