Unrated severityNVD Advisory· Published Jan 6, 2012· Updated Jun 16, 2026
CVE-2012-0287
CVE-2012-0287
Description
Cross-site scripting (XSS) vulnerability in wp-comments-post.php in WordPress 3.3.x before 3.3.1, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via the query string in a POST operation that is not properly handled by the "Duplicate comment detected" feature.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2cpe:2.3:a:wordpress:wordpress:3.3:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:wordpress:wordpress:3.3:*:*:*:*:*:*:*
- (no CPE)range: >=3.3 <3.3.1
Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.