CVE-2007-1049
wordpress - cross-site scripting
EPSS 6.2%
Description
Cross-site scripting (XSS) vulnerability in the wp_explain_nonce function in the nonce AYS functionality (wp-includes/functions.php) for WordPress 2.0 before 2.0.9 and 2.1 before 2.1.1 allows remote attackers to inject arbitrary web script or HTML via the file parameter to wp-admin/templates.php, and possibly other vectors involving the action variable.
How to fix CVE-2007-1049
To remediate CVE-2007-1049, upgrade the affected package to a fixed version below.
- Debian/wordpress—upgrade to 2.1.1-1 or later
- Debian/wordpress—upgrade to 2.0.9-1 or later
Is CVE-2007-1049 being exploited?
Moderate — EPSS is 6.2%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (2)
- from 0, < 2.1.1-1
- from 0, < 2.0.9-1