CVE-2007-3238
EPSS 1.5%
Description
Cross-site scripting (XSS) vulnerability in functions.php in the default theme in WordPress 2.2 allows remote authenticated administrators to inject arbitrary web script or HTML via the PATH_INFO (REQUEST_URI) to wp-admin/themes.php, a different vulnerability than CVE-2007-1622. NOTE: this might not cross privilege boundaries in some configurations, since the Administrator role has the unfiltered_html capability.
How to fix CVE-2007-3238
To remediate CVE-2007-3238, upgrade the affected package to a fixed version below.
- Debian/wordpress—upgrade to 2.2.2-1 or later
Is CVE-2007-3238 being exploited?
Low — EPSS is 1.5%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 2.2.2-1