WordPress component: Cross-site scripting
WordPress component is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
- Component
- WordPress component
- Plugin slug
Core- Affected
- See vendor advisory
- Safe version
- See mitigation notes
- Published
- Dec 31, 2004
- Weakness
- NVD-CWE-Other
This CVE was published Dec 31, 2004 and is one of 45 known issues for WordPress core.
Patch or disable the affected component.
Update WordPress component to a release outside the affected range, or disable and remove it until a fixed version is available.
Technical description
Multiple cross-site scripting (XSS) vulnerabilities in Wordpress 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) redirect_to, text, popupurl, or popuptitle parameters to wp-login.php, (2) redirect_url parameter to admin-header.php, (3) popuptitle, popupurl, content, or post_title parameters to bookmarklet.php, (4) cat_ID parameter to categories.php, (5) s parameter to edit.php, or (6) s or mode parameter to edit-comments.php.
NVD vector: AV:N/AC:M/Au:N/C:N/I:P/A:N
Primary and upstream sources
- NVD record for CVE-2004-1559
- Upstream reference marc.info
- Upstream reference secunia.com
- Upstream reference securitytracker.com
- Upstream reference securityfocus.com
- Upstream reference exchange.xforce.ibmcloud.com
- Upstream reference marc.info
- Upstream reference secunia.com
- Upstream reference securitytracker.com
- Upstream reference securityfocus.com
- Upstream reference exchange.xforce.ibmcloud.com