Description
WordPress is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user. This may help the attacker steal cookie-based authentication credentials and launch other attacks. WordPress version 2.1 is vulnerable; prior versions may also be affected.
Remediation
Update to WordPress version 2.1.1 or latest
References
Related Vulnerabilities
WordPress Plugin Yakadanda Google+ Hangout Events Cross-Site Scripting (0.3.7)
Artifactory CVE-2019-9733 Vulnerability (CVE-2019-9733)
WordPress Plugin Royal Gallery 'upload.php' Arbitrary File Upload (2.1)
MySQL Other Vulnerability (CVE-2007-6303)
WordPress Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2020-28040)