WordPress · Sabre Plugin · CVE-2012-2916
**Name of the Vulnerable Software and Affected Versions**
SABRE plugin versions prior to 2.1 for WordPress
**Description**
The issue is related to a cross-site scripting (XSS) vulnerability. This vulnerability allows remote attackers to inject arbitrary web script or HTML via the `active option` parameter to "wp-admin/tools.php".
**Recommendations**
For SABRE plugin versions prior to 2.1, update to version 2.1 or later to resolve the issue.