CVE-2016-1000132 is a reflected Cross-Site Scripting (XSS) vulnerability found in version 3.2.8 of the WordPress Enhanced Tooltip and Glossary plugin. This medium-severity vulnerability (CVSS 6.1) allows an unauthenticated attacker to inject malicious scripts into a user's browser via a crafted URL, requiring user interaction. While no active exploitation or public exploit code (Metasploit, ExploitDB) has been identified, and community discussion is minimal, a Nuclei template exists for detection. Organizations using the affected plugin should prioritize patching to mitigate the risk of client-side attacks.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.2.8CPE matchmatch criteria | cpe:2.3:a:cminds:tooltip_glossary:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.