WordPress 2.6.3 Vulnerable to XSS in RSS FG
Nov.26, 2008 in
Disclosure, Pentesting, Vulnerabilities, Web Application
It has been reported here (but I first saw it here) that WordPress, a popular blogging application is vulnerable to cross-site scripting (XSS). The vulnerability, discovered in the RSS feed generator and complete with a PoC, affects all versions prior to and including version 2.6.3. A week after the vendor (WordPress) was notified, it released a new version (2.6.5).
Related Posts







Leave a Reply