4.3
CVSSv2

CVE-2007-4893

Published: 14/09/2007 Updated: 29/07/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

wp-admin/admin-functions.php in Wordpress prior to 2.2.3 and Wordpress multi-user (MU) prior to 1.2.5a does not properly verify the unfiltered_html privilege, which allows remote malicious users to conduct cross-site scripting (XSS) attacks via modified data to (1) post.php or (2) page.php with a no_filter field.

Vulnerable Product Search on Vulmon Subscribe to Product

wordpress wordpress 1.2.1

wordpress wordpress 1.2.2

wordpress wordpress 2.0.10_rc2

wordpress wordpress 2.0.2

wordpress wordpress 2.1.2

wordpress wordpress 2.1.3

wordpress wordpress 2.2_revision5003

wordpress wordpress 0.6.2.1

wordpress wordpress 0.7

wordpress wordpress 1.5.1.3

wordpress wordpress 2.0

wordpress wordpress 2.0.5

wordpress wordpress 2.0.6

wordpress wordpress 2.2

wordpress wordpress 2.2.1

wordpress wordpress 0.6.2

wordpress wordpress 0.71

wordpress wordpress 1.2

wordpress wordpress 2.0.1

wordpress wordpress 2.0.10_rc1

wordpress wordpress 2.0.7

wordpress wordpress 2.1.1

wordpress wordpress 2.2.2

wordpress wordpress 2.2_revision5002

wordpress wordpress 1.5

wordpress wordpress 1.5.1

wordpress wordpress 1.5.1.2

wordpress wordpress 2.0.3

wordpress wordpress 2.0.4

wordpress wordpress 2.1.3_rc1

wordpress wordpress 2.1.3_rc2