CVE-2007-3240: XSS
Cross-site scripting (XSS) vulnerability in 404.php in the Vistered-Little theme for WordPress allows remote attackers to inject arbitrary web script or HTML via the URI (REQUESTURI) that accesses index.php. NOTE: this can be leveraged for PHP code execution in an administrative session.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-3240?
CVE-2007-3240 is classified as a high severity vulnerability due to its potential for remote code execution and cross-site scripting attacks.
How do I fix CVE-2007-3240?
To fix CVE-2007-3240, update the Vistered-Little theme and ensure your WordPress installation is at least version 2.2 or higher.
What kind of attacks can be performed using CVE-2007-3240?
Attackers can exploit CVE-2007-3240 to inject arbitrary web scripts or HTML, potentially leading to session hijacking or data theft.
Which versions of WordPress are affected by CVE-2007-3240?
CVE-2007-3240 specifically affects WordPress version 2.2 when using the Vistered-Little theme.
Can CVE-2007-3240 be used for PHP code execution?
Yes, CVE-2007-3240 can be leveraged for PHP code execution within an administrative session.