CVE-2011-5182
Cross-site scripting (XSS) vulnerability in lanoba-social-plugin/index.php in the Lanoba Social plugin 1.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via the action parameter. NOTE: the vendor disputes this issue, stating "Lanoba's plug in does sanitize user input, and because that input is never sent to the browser, an attacker has no way of executing script or code on a user's behalf.
CVSS
- Version: 2.0
- Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N
- Base score: 4.3
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 3.60%
- Percentile among all scored CVEs: 89
- Score date: 10/8/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
💥 Public exploits
Exploit code or detection templates are publicly available. This is not the same as confirmed active exploitation (KEV), but it raises the risk: patch with priority.
- Published on Exploit-DB · WordPress Plugin Lanoba Social 1.0 - 'action' Cross-Site Scripting (11/21/2011)
Affected technologies (1)
CWEs
- CWE-79
References
- http://www.securityfocus.com/archive/1/520574/100/0/threaded
- http://www.securityfocus.com/archive/1/520678/100/0/threaded
- http://www.securityfocus.com/bid/50746
- https://exchange.xforce.ibmcloud.com/vulnerabilities/71411
- https://wordpress.org/support/topic/plugin-lanoba-social-plugin-xss-vulnerabilities
- http://www.securityfocus.com/archive/1/520574/100/0/threaded
- http://www.securityfocus.com/archive/1/520678/100/0/threaded
- http://www.securityfocus.com/bid/50746
- https://exchange.xforce.ibmcloud.com/vulnerabilities/71411
- https://wordpress.org/support/topic/plugin-lanoba-social-plugin-xss-vulnerabilities
Raw JSON (NVD)
Show
{
"id": "CVE-2011-5182",
"cveTags": [
{
"tags": [
"disputed"
],
"sourceIdentifier": "cve@mitre.org"
}
],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2012-09-20T10:55:26.820",
"references": [
{
"url": "http://www.securityfocus.com/archive/1/520574/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/520678/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/50746",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/71411",
"source": "cve@mitre.org"
},
{
"url": "https://wordpress.org/support/topic/plugin-lanoba-social-plugin-xss-vulnerabilities",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/520574/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/520678/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/50746",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/71411",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://wordpress.org/support/topic/plugin-lanoba-social-plugin-xss-vulnerabilities",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Cross-site scripting (XSS) vulnerability in lanoba-social-plugin/index.php in the Lanoba Social plugin 1.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via the action parameter. NOTE: the vendor disputes this issue, stating \"Lanoba's plug in does sanitize user input, and because that input is never sent to the browser, an attacker has no way of executing script or code on a user's behalf."
},
{
"lang": "es",
"value": "** EN DISPUTA ** Una vulnerabilidad de ejecución de comandos en sitios cruzados (XSS) en lanoba-social-plugin/index.php en el plugin Lanoba Social para WordPress v1.0, permite a atacantes remotos inyectar secuencias de comandos web o HTML a través del parámetro 'action'. NOTA: El vendendor no esta de acuerdo con este problema, alegando que Lanoba no limpia la entrada del usuario, y debido a que la entrada nunca se envía al navegador, un atacante no tiene manera de ejecutar un script o cualquier tipo de código en nombre de otro usuario\"."
}
],
"lastModified": "2026-06-16T23:36:06.103",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:wordpress:lanoba_social_plugin:1.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CAAE0FD4-E430-4713-BE3D-5004221EA89E"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:wordpress:wordpress:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "A77EB0E7-7FA7-4232-97DF-7C7587D163F1"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "cve@mitre.org"
}