- WordPress is prone to a vulnerability which can be exploited by malicious people to cause a Denial of Service. The vulnerability is caused due to the 'wp-trackback.php' script letting users pass multiple source character encodings to the "mb_convert_encoding()" function, which can be used to cause a high CPU load, potentially resulting in a DoS, thus denying service to legitimate users. WordPress versions prior to 2.8.5 are vulnerable.
- Update to WordPress version 2.8.5 or latest
- WordPress Plugin Count per Day 'userperspan.php' Multiple Cross-Site Scripting Vulnerabilities (3.1.1)
- Joomla! Core 1.0.x SQL Injection (1.0.0 - 1.0.11)
- WordPress Plugin Crowd Ideas Cross-Site Scripting (1.0)
- WordPress Plugin Testimonials by BestWebSoft Cross-Site Scripting (0.1.8)
- WordPress Plugin WP Maintenance Mode Multiple Vulnerabilities (2.0.3)