Unrated severityNVD Advisory· Published Feb 14, 2012· Updated Jun 16, 2026
CVE-2012-1068
CVE-2012-1068
Description
Cross-site scripting (XSS) vulnerability in the rc_ajax function in core.php in the WP-RecentComments plugin before 2.0.7 for WordPress allows remote attackers to inject arbitrary web script or HTML via the page parameter, related to AJAX paging.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2<2.0.7+ 1 more
- (no CPE)range: <2.0.7
- (no CPE)range: <2.0.7
Patches
Vulnerability mechanics
References
6News mentions
0No linked articles in our index yet.