Description
Multiple cross-site scripting (XSS) vulnerabilities in the "post comment" functionality of WordPress 2.0.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) website, and (3) comment parameters.
Remediation
References
Related Vulnerabilities
TYPO3 Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2010-1153)
WordPress Cryptographic Issues Vulnerability (CVE-2014-9037)
WordPress Plugin Answer My Question Cross-Site Scripting (1.3)
MySQL CVE-2016-0668 Vulnerability (CVE-2016-0668)
WordPress Plugin AccessPress Social Counter Cross-Site Scripting (1.3.6)