Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.5.1 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) gallery shortcodes or (2) the content of a post.
http://www.cvedetails.com/cve/CVE-2013-0236/
http://core.trac.wordpress.org/changeset/23322/branches/3.5
This vulnerability affects the following application versions:
- WordPress 3.5