CVE-2012-2401: Moxiecode Plupload
Medium severity, CVSS 5.0. EPSS: 3.4% chance of exploitation in the next 30 days.
Plupload before 1.5.4, as used in wp-includes/js/plupload/ in WordPress before 3.3.2 and other products, enables scripting regardless of the domain from which the SWF content was loaded, which allows remote attackers to bypass the Same Origin Policy via crafted content.
Affected products
- Moxiecode Plupload: up to and including 1.5.3; version 1.4.0 only; version 1.4.1 only; version 1.4.2 only; version 1.4.3 only; version 1.5.0 only; …
- WordPress WordPress: up to and including 3.3.1; version 0.71 only; version 1.0 only; version 1.0.1 only; version 1.0.2 only; version 1.1.1 only; …
Published 2012-04-21. Last modified 2026-06-16.