Description
WordPress is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user. This may help the attacker steal cookie-based authentication credentials and launch other attacks. WordPress version 2.1 is vulnerable; prior versions may also be affected.
Remediation
Update to WordPress version 2.1.1 or latest
References
Related Vulnerabilities
WordPress Plugin Related Posts Unspecified Vulnerability (5.12.69)
WordPress Plugin MiwoFTP-File & Folder Manager Arbitrary File Download (1.0.5)
Grafana Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2026-27876)
MySQL CVE-2019-2966 Vulnerability (CVE-2019-2966)
WordPress Plugin WP Web Scraper Unspecified Vulnerability (2.4)