CVE-2010-5294
EPSS 0.71%
Description
Multiple cross-site scripting (XSS) vulnerabilities in the request_filesystem_credentials function in wp-admin/includes/file.php in WordPress before 3.0.2 allow remote servers to inject arbitrary web script or HTML by providing a crafted error message for a (1) FTP or (2) SSH connection attempt.
How to fix CVE-2010-5294
To remediate CVE-2010-5294, upgrade the affected package to a fixed version below.
- Debian/wordpress—upgrade to 3.0.2-1 or later
Is CVE-2010-5294 being exploited?
Low — EPSS is 0.7%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 3.0.2-1