Cross-site scripting (XSS) vulnerability in uploadify/get_profile_avatar.php in the WP Symposium plugin before 11.12.08 for WordPress allows remote attackers to inject arbitrary web script or HTML via the uid parameter.Referenceshttp://www.securityfocus.com/bid/51017http://secunia.com/advisories/47243http://www.wpsymposium.com/2011/12/v11-12-08/https://exchange.xforce.ibmcloud.com/vulnerabilities/71748http://secunia.com/secunia_research/2011-82/