CVE-2012-1834: CMS Tree Page View Project CMS Tree Page View

Medium severity, CVSS 4.3. EPSS: 2.4% chance of exploitation in the next 30 days.

Cross-site scripting (XSS) vulnerability in the cms_tpv_admin_head function in functions.php in the CMS Tree Page View plugin before 0.8.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the cms_tpv_view parameter to wp-admin/options-general.php.

Affected products

  • CMS Tree Page View Project CMS Tree Page View: up to and including 0.8.8; version 0.1 only; version 0.1a only; version 0.2 only; version 0.3 only; version 0.4 only; …

Published 2014-04-07. Last modified 2026-06-16.