CVE-2012-1834

medium
Published 2014-04-07 ยท Modified 2026-05-06
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
4.3

Description

Cross-site scripting (XSS) vulnerability in the cms_tpv_admin_head function in functions.php in the CMS Tree Page View plugin before 0.8.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the cms_tpv_view parameter to wp-admin/options-general.php.

Predictions

Exploit likelihood
20%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ€” if you've already worked around this in production โ€” publish your fix to the community-verified tier.

โœš Propose a mitigation on Community โ†’ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

Application impact

VendorProductVersionsFixed
cms_tree_page_view_projectcms_tree_page_view{"endIncluding":"0.8.8"}
cms_tree_page_view_projectcms_tree_page_view0.1
cms_tree_page_view_projectcms_tree_page_view0.1a
cms_tree_page_view_projectcms_tree_page_view0.2
cms_tree_page_view_projectcms_tree_page_view0.3
cms_tree_page_view_projectcms_tree_page_view0.4
cms_tree_page_view_projectcms_tree_page_view0.4.1
cms_tree_page_view_projectcms_tree_page_view0.4.2
cms_tree_page_view_projectcms_tree_page_view0.4.3
cms_tree_page_view_projectcms_tree_page_view0.4.4
cms_tree_page_view_projectcms_tree_page_view0.4.5
cms_tree_page_view_projectcms_tree_page_view0.4.6
cms_tree_page_view_projectcms_tree_page_view0.4.7
cms_tree_page_view_projectcms_tree_page_view0.4.8
cms_tree_page_view_projectcms_tree_page_view0.4.9
cms_tree_page_view_projectcms_tree_page_view0.5
cms_tree_page_view_projectcms_tree_page_view0.5.1
cms_tree_page_view_projectcms_tree_page_view0.5.2
cms_tree_page_view_projectcms_tree_page_view0.5.3
cms_tree_page_view_projectcms_tree_page_view0.5.4
cms_tree_page_view_projectcms_tree_page_view0.5.5
cms_tree_page_view_projectcms_tree_page_view0.5.6
cms_tree_page_view_projectcms_tree_page_view0.5.7
cms_tree_page_view_projectcms_tree_page_view0.6
cms_tree_page_view_projectcms_tree_page_view0.6.1
cms_tree_page_view_projectcms_tree_page_view0.6.2
cms_tree_page_view_projectcms_tree_page_view0.6.3
cms_tree_page_view_projectcms_tree_page_view0.7
cms_tree_page_view_projectcms_tree_page_view0.7.1
cms_tree_page_view_projectcms_tree_page_view0.7.2
cms_tree_page_view_projectcms_tree_page_view0.7.3
cms_tree_page_view_projectcms_tree_page_view0.7.4
cms_tree_page_view_projectcms_tree_page_view0.7.5
cms_tree_page_view_projectcms_tree_page_view0.7.6
cms_tree_page_view_projectcms_tree_page_view0.7.7
cms_tree_page_view_projectcms_tree_page_view0.7.8
cms_tree_page_view_projectcms_tree_page_view0.7.9
cms_tree_page_view_projectcms_tree_page_view0.7.10
cms_tree_page_view_projectcms_tree_page_view0.7.11
cms_tree_page_view_projectcms_tree_page_view0.7.12
cms_tree_page_view_projectcms_tree_page_view0.7.13
cms_tree_page_view_projectcms_tree_page_view0.7.14
cms_tree_page_view_projectcms_tree_page_view0.7.15
cms_tree_page_view_projectcms_tree_page_view0.7.16
cms_tree_page_view_projectcms_tree_page_view0.7.17
cms_tree_page_view_projectcms_tree_page_view0.7.18
cms_tree_page_view_projectcms_tree_page_view0.7.19
cms_tree_page_view_projectcms_tree_page_view0.7.20
cms_tree_page_view_projectcms_tree_page_view0.8
cms_tree_page_view_projectcms_tree_page_view0.8.1
cms_tree_page_view_projectcms_tree_page_view0.8.2
cms_tree_page_view_projectcms_tree_page_view0.8.3
cms_tree_page_view_projectcms_tree_page_view0.8.4
cms_tree_page_view_projectcms_tree_page_view0.8.5
cms_tree_page_view_projectcms_tree_page_view0.8.6
cms_tree_page_view_projectcms_tree_page_view0.8.7

References

CWEs

CWE-79

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.