Lucene search

K
patchstackAlexander ConchaPATCHSTACK:5F68D259B420346211F71A2A6663747B
HistoryMar 22, 2007 - 12:00 a.m.

WordPress <= 2.1.2 RC2 - XSS

2007-03-2200:00:00
Alexander Concha
patchstack.com
10

0.01 Low

EPSS

Percentile

83.9%

Because of this vulnerability in wp-admin/vars.php, the authenticated users with theme privileges can inject arbitrary web script or HTML via the PATH_INFO.

Solution

           Update the WordPress to the latest available version (at least 2.1.3).
CPENameOperatorVersion
wordpressle2.1.2 RC2

0.01 Low

EPSS

Percentile

83.9%

Related for PATCHSTACK:5F68D259B420346211F71A2A6663747B