{
  "modified": "2025-08-09T19:01:27Z",
  "published": "2013-07-08T20:55:00Z",
  "id": "CVE-2013-0236",
  "details": "Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.5.1 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) gallery shortcodes or (2) the content of a post.",
  "references": [
    {
      "type": "ADVISORY",
      "url": "http://wordpress.org/news/2013/01/wordpress-3-5-1/"
    },
    {
      "type": "EVIDENCE",
      "url": "http://core.trac.wordpress.org/changeset/23322"
    },
    {
      "type": "FIX",
      "url": "http://core.trac.wordpress.org/changeset/23317"
    },
    {
      "type": "FIX",
      "url": "http://core.trac.wordpress.org/changeset/23322"
    },
    {
      "type": "REPORT",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=904121"
    },
    {
      "type": "WEB",
      "url": "http://codex.wordpress.org/Version_3.5.1"
    }
  ]
}
