CVE-2007-1622: XSS

Published Mar 23, 2007
·
Updated

Cross-site scripting (XSS) vulnerability in wp-admin/vars.php in WordPress before 2.0.10 RC2, and before 2.1.3 RC2 in the 2.1 series, allows remote authenticated users with theme privileges to inject arbitrary web script or HTML via the PATHINFO in the administration interface, related to loose regular expression processing of PHPSELF.

Affected Software

14 affected components
WordPress=2.0
WordPress=2.0.1
WordPress=2.0.2
WordPress=2.0.3
WordPress=2.0.4
WordPress=2.0.5
WordPress=2.0.6
WordPress=2.0.7
WordPress=2.0.10
WordPress=2.0.10_rc1
WordPress=2.1
WordPress=2.1.1
WordPress=2.1.2
WordPress=2.1.3_rc1

Event History

Mar 23, 2007
CVE Published
12:19 AM
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-2007-1622?

CVE-2007-1622 has a medium severity rating due to its impact on the security of WordPress admin interface.

2

How do I fix CVE-2007-1622?

To fix CVE-2007-1622, upgrade WordPress to version 2.0.10 or later, or 2.1.3 RC2 or later.

3

What type of vulnerability is CVE-2007-1622?

CVE-2007-1622 is a cross-site scripting (XSS) vulnerability affecting WordPress.

4

Who is affected by CVE-2007-1622?

Remote authenticated users with theme privileges in WordPress prior to the patched versions are affected by CVE-2007-1622.

5

What versions of WordPress are affected by CVE-2007-1622?

WordPress versions prior to 2.0.10 and 2.1.3 RC2 are affected by CVE-2007-1622.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203