MEDIUM
Cross-site scripting (XSS) vulnerability in sidebar.php in WordPress, when custom 404 pages that call get_sidebar are used, allows remote attackers to inject arbitrary web script or HTML via the query string (PHP_SELF), a different vulnerability than CVE-2007-1622
Published May 11, 2007
6.8
MEDIUMCVSS 2.0
EPSS 2.33%
Description
Affected products
Remediation
Metrics
References (3)
Change history (0)
No recorded changes yet.