Unrated severityNVD Advisory· Published Aug 13, 2012· Updated Apr 29, 2026
CVE-2012-4268
CVE-2012-4268
Description
Cross-site scripting (XSS) vulnerability in bulletproof-security/admin/options.php in the BulletProof Security plugin before .47.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the HTTP_ACCEPT_ENCODING header.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- packetstormsecurity.org/files/112618/WordPress-BulletProof-Security-Cross-Site-Scripting.htmlnvdExploit
- plugins.trac.wordpress.org/changesetnvdExploitPatch
- wordpress.org/extend/plugins/bulletproof-security/changelog/nvd
- www.securityfocus.com/bid/53478nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/75522nvd
News mentions
0No linked articles in our index yet.