CVE-2006-1796: XSS
Cross-site scripting (XSS) vulnerability in the paging links functionality in template-functions-links.php in Wordpress 1.5.2, and possibly other versions before 2.0.1, allows remote attackers to inject arbitrary web script or HTML to Internet Explorer users via the request URI ($SERVER['REQUESTURI']).
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-1796?
CVE-2006-1796 is classified as a medium-severity vulnerability due to its impact on user data via cross-site scripting.
How do I fix CVE-2006-1796?
To fix CVE-2006-1796, upgrade your WordPress installation to version 2.0.1 or later.
Which versions of WordPress are affected by CVE-2006-1796?
CVE-2006-1796 affects WordPress versions prior to 2.0.1, including 1.5.2 and several earlier versions.
What types of attacks can exploit CVE-2006-1796?
CVE-2006-1796 can be exploited to inject arbitrary web scripts or HTML through the request URI, leading to cross-site scripting attacks.
Can I use older versions of WordPress if I mitigate CVE-2006-1796?
Using older versions of WordPress is not recommended as CVE-2006-1796 and other vulnerabilities may expose your site to risk.