Description
WordPress Plugin Comment System for WordPress & Ajax Comments-Comment Press is prone to a cross-frame scripting vulnerability. Exploiting this issue may allow a remote attacker to steal user credentials from an unsuspecting user. This attack is usually successful only when combined with social engineering. WordPress Plugin Comment System for WordPress & Ajax Comments-Comment Press version 2.7.0 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.7.2 or latest
References
Related Vulnerabilities
Microsoft SQL Server Other Vulnerability (CVE-2000-1082)
phpMyAdmin Improper Restriction of XML External Entity Reference Vulnerability (CVE-2011-4107)
Python Missing Initialization of Resource Vulnerability (CVE-2018-14647)
WordPress Plugin Registrations for the Events Calendar-Event Registration SQL Injection (2.7.5)