CVE-2007-3639: Medium severity WordPress vulnerability
WordPress before 2.2.2 allows remote attackers to redirect visitors to other websites and potentially obtain sensitive information via (1) the wphttpreferer parameter to wp-pass.php, related to the wpgetreferer function in wp-includes/functions.php; and possibly other vectors related to (2) wp-includes/pluggable.php and (3) the wpnonceays function in wp-includes/functions.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-3639?
CVE-2007-3639 is considered a medium severity vulnerability that can lead to information disclosure and redirection attacks.
How do I fix CVE-2007-3639?
To mitigate CVE-2007-3639, upgrade WordPress to version 2.2.2 or later.
Who is affected by CVE-2007-3639?
CVE-2007-3639 affects all versions of WordPress prior to 2.2.2.
What types of attacks can be executed using CVE-2007-3639?
Attackers can exploit CVE-2007-3639 to redirect users to malicious websites and potentially obtain sensitive information.
What steps can I take to protect my website from CVE-2007-3639?
Ensure that your WordPress installation is updated to the latest version to protect against CVE-2007-3639.