WordPress 'templates.php' Cross-Site Scripting Vulnerability (0.6.2 - 2.1)

Description

WordPress is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user. This may help the attacker steal cookie-based authentication credentials and launch other attacks. WordPress version 2.1 is vulnerable; prior versions may also be affected.

Remediation

Update to WordPress version 2.1.1 or latest

References