PT-2006-1785 · WordPress+1 · Wordpress+1

Published

2006-02-16

·

Updated

2024-08-07

·

CVE-2006-0733

CVSS v2.0

2.6

Low

VectorAV:N/AC:H/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions WordPress version 2.0.0
Description A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary web script or HTML via scriptable attributes such as onfocus and onblur in the "author's website" field. It is suggested that this issue might only be exploitable by the same user who injects the XSS.
Recommendations For WordPress version 2.0.0, consider restricting the use of scriptable attributes in the "author's website" field to minimize the risk of exploitation. As a temporary workaround, disabling the ability to input scriptable attributes such as onfocus and onblur in this field may help until a more permanent solution is available.

Exploit

Fix

Related Identifiers

CVE-2006-0733

Affected Products

Debian
Wordpress