CVE-2012-4226
Status: ModifiedMedium (4.3)—
Multiple cross-site scripting (XSS) vulnerabilities in Quick Post Widget plugin 1.9.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) Title, (2) Content, or (3) New category field to wordpress/ or (4) query string to wordpress/.
CVSS
- Version: 2.0
- Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N
- Base score: 4.3
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 2.04%
- Percentile among all scored CVEs: 81
- Score date: 10/8/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-79
References
- http://archives.neohapsis.com/archives/bugtraq/2012-08/0067.html
- http://packetstormsecurity.com/files/115463/WordPress-Quick-Post-Widget-1.9.1-Cross-Site-Scripting.html
- http://www.darksecurity.de/advisories/2012/SSCHADV2012-016.txt
- http://www.securityfocus.com/bid/54311
- https://exchange.xforce.ibmcloud.com/vulnerabilities/77731
- http://archives.neohapsis.com/archives/bugtraq/2012-08/0067.html
- http://packetstormsecurity.com/files/115463/WordPress-Quick-Post-Widget-1.9.1-Cross-Site-Scripting.html
- http://www.darksecurity.de/advisories/2012/SSCHADV2012-016.txt
- http://www.securityfocus.com/bid/54311
- https://exchange.xforce.ibmcloud.com/vulnerabilities/77731
Raw JSON (NVD)
Show
{
"id": "CVE-2012-4226",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2014-09-03T14:55:04.273",
"references": [
{
"url": "http://archives.neohapsis.com/archives/bugtraq/2012-08/0067.html",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://packetstormsecurity.com/files/115463/WordPress-Quick-Post-Widget-1.9.1-Cross-Site-Scripting.html",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.darksecurity.de/advisories/2012/SSCHADV2012-016.txt",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/54311",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/77731",
"source": "cve@mitre.org"
},
{
"url": "http://archives.neohapsis.com/archives/bugtraq/2012-08/0067.html",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://packetstormsecurity.com/files/115463/WordPress-Quick-Post-Widget-1.9.1-Cross-Site-Scripting.html",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.darksecurity.de/advisories/2012/SSCHADV2012-016.txt",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/54311",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/77731",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Multiple cross-site scripting (XSS) vulnerabilities in Quick Post Widget plugin 1.9.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) Title, (2) Content, or (3) New category field to wordpress/ or (4) query string to wordpress/."
},
{
"lang": "es",
"value": "Múltiples vulnerabilidades de XSS en el plugin Quick Post Widget 1.9.1 para WordPress permiten a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a través del campo (1) Title, (2) Content, o (3) New category en wordpress/ o la cadena (4) query en wordpress/."
}
],
"lastModified": "2026-06-16T23:44:39.920",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:qpw.famvanakkeren:quick_post_widget:1.9.1:*:*:*:*:wordpress:*:*",
"vulnerable": true,
"matchCriteriaId": "3A99F308-2659-44A6-9BB6-8A5792526613"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}