Latest Exploit In Wordpress

by Gobala Krishnan on January 3, 2007

in Blogging Tips

A Cross-site scripting (XSS) vulnerability has been discovered in wp-admin/templates.php in WordPress which affect all version till 2.0.5.

Wordpress is prone to a HTML-injection scripting vulnerability because the application fails to properly sanitize user-supplied input.

Attacker-supplied HTML and script code would execute in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.

Versions prior to 2.0.6 are vulnerable to this issue.

source – Security Focus

According to LiewCF, The National Vulnerability Database has reported this as severity 7.0 (high).

I “strongly” encourage wordpress users to apply the Latest Patch ASAP!! Just download the necessary file and overwrite the existing.

VN:F [1.4.4_707]
Rating: 0.0/5 (0 votes cast)

Share This Post

Leave a Comment

You can use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

Previous post: Auto Social Poster Version 1.5 Allows Future Posts

Next post: Wordpress 2.0.6 Is Out!!