A cross-site scripting vulnerability in yousaytoo.php in YouSayToo auto-publishing plugin 1.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via the submit parameter.
View the template here CVE-2012-0901.yaml
References:
https://nvd.nist.gov/vuln/detail/CVE-2012-0901