Description
Multiple cross-site scripting (XSS) vulnerabilities in the "post comment" functionality of WordPress 2.0.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) website, and (3) comment parameters.
Remediation
References
Related Vulnerabilities
MediaWiki Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-1581)
WordPress Permissions, Privileges, and Access Controls Vulnerability (CVE-2008-2146)
Moodle Improper Control of Generation of Code (Code Injection) (CVE-2019-14827)
WordPress Plugin Thrive Dashboard Security Bypass (2.3.9.2)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2011-4589)