WordPress component: Cross-site scripting
WordPress component is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
- Component
- WordPress component
- Plugin slug
Core- Affected
- See vendor advisory
- Safe version
- See mitigation notes
- Published
- Mar 12, 2008
This CVE was published Mar 12, 2008 and is one of 45 known issues for WordPress core.
Patch or disable the affected component.
Update WordPress component to a release outside the affected range, or disable and remove it until a fixed version is available.
Technical description
Multiple cross-site scripting (XSS) vulnerabilities in WordPress 2.3.2 allow remote attackers to inject arbitrary web script or HTML via the (1) inviteemail parameter in an invite action to wp-admin/users.php and the (2) to parameter in a sent action to wp-admin/invites.php.
NVD vector: AV:N/AC:M/Au:N/C:N/I:P/A:N
Primary and upstream sources
- NVD record for CVE-2008-1304
- Upstream reference securityreason.com
- Upstream reference securitytracker.com
- Upstream reference hackerscenter.com
- Upstream reference securityfocus.com
- Upstream reference securityfocus.com
- Upstream reference exchange.xforce.ibmcloud.com
- Upstream reference exchange.xforce.ibmcloud.com
- Upstream reference securityreason.com
- Upstream reference securitytracker.com
- Upstream reference hackerscenter.com
- Upstream reference securityfocus.com
- Upstream reference securityfocus.com
- Upstream reference exchange.xforce.ibmcloud.com
- Upstream reference exchange.xforce.ibmcloud.com