Lucene search

K
osvGoogleOSV:DSA-1601-1
HistoryJul 04, 2008 - 12:00 a.m.

wordpress - several vulnerabilities

2008-07-0400:00:00
Google
osv.dev
10

0.007 Low

EPSS

Percentile

80.1%

Several remote vulnerabilities have been discovered in Wordpress,
the weblog manager. The Common Vulnerabilities and Exposures project
identifies the following problems:

  • CVE-2007-1599
    WordPress allows remote attackers to redirect authenticated users
    to other websites and potentially obtain sensitive information.
  • CVE-2008-0664
    The XML-RPC implementation, when registration is enabled, allows
    remote attackers to edit posts of other blog users.

For the stable distribution (etch), these problems have been fixed in
version 2.0.10-1etch3.

For the unstable distribution (sid), these problems have been fixed in
version 2.3.3-1.

We recommend that you upgrade your wordpress package.