Description
WordPress is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user. This may help the attacker steal cookie-based authentication credentials and launch other attacks. WordPress version 2.1.1 is vulnerable; other versions may also be affected.
Remediation
Update to WordPress version 2.1.2 or latest
References
http://www.securityfocus.com/archive/1/461440
http://packetstormsecurity.org/files/view/54793/wp211-csrfxss.txt
Related Vulnerabilities
Jboss EAP Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-4549)
Jboss EAP Deserialization of Untrusted Data Vulnerability (CVE-2016-4978)
MySQL CVE-2018-3073 Vulnerability (CVE-2018-3073)
MySQL CVE-2016-5627 Vulnerability (CVE-2016-5627)
WordPress Plugin WooCommerce Smart Coupons Security Bypass (4.6.0)