PoC Index

CVE-2013-2202

MEDIUM 4.3EPSS 2.2%

WordPress before 3.5.2 allows remote attackers to read arbitrary files via an oEmbed XML provider response containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

CVSS v2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
EPSS
2.25% chance of exploitation in the next 30 days, 82th percentile
Nuclei
medium
Published
2013-07-08
Updated
2024-08-06

Nuclei templates (1)

References

Related