{"api_version":"1","generated_at":"2026-07-23T05:38:08+00:00","cve":"CVE-2012-2580","urls":{"html":"https://cve.report/CVE-2012-2580","api":"https://cve.report/api/cve/CVE-2012-2580.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2012-2580","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2012-2580"},"summary":{"title":"CVE-2012-2580","description":"Cross-site scripting (XSS) vulnerability in the Postie plugin 1.4.3, and possibly before 1.5.15, for WordPress allows remote attackers to inject arbitrary web script or HTML via the From field of an email.","state":"PUBLISHED","assigner":"certcc","published_at":"2014-06-20 14:55:05","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.exploit-db.com/exploits/20360","name":"http://www.exploit-db.com/exploits/20360","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Wordpress Postie Plugin 1.4.3 Stored XSS","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/54909","name":"http://www.securityfocus.com/bid/54909","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Wordpress Postie Plugin 'From' Field HTML Injection Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/77537","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/77537","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/50207","name":"http://secunia.com/advisories/50207","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Security Alerts - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/84532","name":"http://osvdb.org/84532","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2012-2580","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2012-2580","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2012","cve_id":"2580","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"postieplugin","cpe5":"postie","cpe6":"1.4.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"wordpress","cpe12":"*","cpe13":"*"},{"cve_year":"2012","cve_id":"2580","vulnerable":"1","versionEndIncluding":"1.5.14","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"postieplugin","cpe5":"postie","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"wordpress","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T19:34:26.015Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"84532","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/84532"},{"name":"postie-wordpress-xss(77537)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/77537"},{"name":"50207","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/50207"},{"name":"54909","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/54909"},{"name":"20360","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"http://www.exploit-db.com/exploits/20360"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2012-08-08T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in the Postie plugin 1.4.3, and possibly before 1.5.15, for WordPress allows remote attackers to inject arbitrary web script or HTML via the From field of an email."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-28T12:57:01.000Z","orgId":"37e5125f-f79b-445b-8fad-9564f167944b","shortName":"certcc"},"references":[{"name":"84532","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/84532"},{"name":"postie-wordpress-xss(77537)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/77537"},{"name":"50207","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/50207"},{"name":"54909","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/54909"},{"name":"20360","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"http://www.exploit-db.com/exploits/20360"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cert@cert.org","ID":"CVE-2012-2580","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in the Postie plugin 1.4.3, and possibly before 1.5.15, for WordPress allows remote attackers to inject arbitrary web script or HTML via the From field of an email."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"84532","refsource":"OSVDB","url":"http://osvdb.org/84532"},{"name":"postie-wordpress-xss(77537)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/77537"},{"name":"50207","refsource":"SECUNIA","url":"http://secunia.com/advisories/50207"},{"name":"54909","refsource":"BID","url":"http://www.securityfocus.com/bid/54909"},{"name":"20360","refsource":"EXPLOIT-DB","url":"http://www.exploit-db.com/exploits/20360"}]}}}},"cveMetadata":{"assignerOrgId":"37e5125f-f79b-445b-8fad-9564f167944b","assignerShortName":"certcc","cveId":"CVE-2012-2580","datePublished":"2014-06-20T14:00:00.000Z","dateReserved":"2012-05-09T00:00:00.000Z","dateUpdated":"2024-08-06T19:34:26.015Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2014-06-20 14:55:05","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:postieplugin:postie:*:*:*:*:*:wordpress:*:*","versionEndIncluding":"1.5.14","matchCriteriaId":"6AB16BBA-7A30-4A0E-A693-B6B040E9A98F"},{"vulnerable":true,"criteria":"cpe:2.3:a:postieplugin:postie:1.4.3:*:*:*:*:wordpress:*:*","matchCriteriaId":"6FF06FA0-A2A9-4DBF-A1D6-DC4C6EC50797"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2012","CveId":"2580","Ordinal":"1","Title":"CVE-2012-2580","CVE":"CVE-2012-2580","Year":"2012"},"notes":[{"CveYear":"2012","CveId":"2580","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in the Postie plugin 1.4.3, and possibly before 1.5.15, for WordPress allows remote attackers to inject arbitrary web script or HTML via the From field of an email.","Type":"Description","Title":"CVE-2012-2580"},{"CveYear":"2012","CveId":"2580","Ordinal":"2","NoteData":"2014-06-20","Type":"Other","Title":"Published"},{"CveYear":"2012","CveId":"2580","Ordinal":"3","NoteData":"2017-08-28","Type":"Other","Title":"Modified"}]}}}