CVE-2007-1732: XSS
DISPUTED Cross-site scripting (XSS) vulnerability in an mt import in wp-admin/admin.php in WordPress 2.1.2 allows remote authenticated administrators to inject arbitrary web script or HTML via the demo parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: another researcher disputes this issue, stating that this is legitimate functionality for administrators. However, it has been patched by at least one vendor.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-1732?
CVE-2007-1732 is considered a moderate severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2007-1732?
To mitigate CVE-2007-1732, upgrade to a newer version of WordPress that does not contain this vulnerability.
Who is affected by CVE-2007-1732?
CVE-2007-1732 specifically affects WordPress version 2.1.2, primarily impacting authenticated administrators.
What type of vulnerability is CVE-2007-1732?
CVE-2007-1732 is a cross-site scripting (XSS) vulnerability.
Can CVE-2007-1732 be exploited remotely?
Yes, CVE-2007-1732 can be exploited remotely by authenticated users who have access to the admin area.