Description
WordPress is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user. This may help the attacker steal cookie-based authentication credentials and launch other attacks. WordPress version 2.1 is vulnerable; prior versions may also be affected.
Remediation
Update to WordPress version 2.1.1 or latest
References
Related Vulnerabilities
WordPress 3.8.x Multiple Vulnerabilities (3.8 - 3.8.30)
WordPress Plugin CataBlog 'category' Parameter Cross-Site Scripting (1.6.2)
TYPO3 Insufficient Session Expiration Vulnerability (CVE-2022-31050)
WordPress Plugin Membership Simplified Arbitrary File Download (1.58)
PostgreSQL Improper Access Control Vulnerability (CVE-2016-7048)