First published: Wed Aug 22 2007(Updated: )
Cross-site scripting (XSS) vulnerability in index.php in the (1) Blix 0.9.1 and (2) Blix 0.9.1 Rus themes for WordPress allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO (PHP_SELF).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Blix | =0.9.1 | |
WordPress Blix | =0.9.1_rus |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-4481 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2007-4481, update the affected Blix theme to the latest version or apply patches that mitigate the XSS vulnerability.
CVE-2007-4481 affects users of the Blix 0.9.1 and Blix 0.9.1 Rus themes for WordPress.
CVE-2007-4481 is a cross-site scripting (XSS) vulnerability allowing attackers to inject arbitrary web scripts or HTML.
The risks associated with CVE-2007-4481 include unauthorized access, data theft, and defacement of websites utilizing the vulnerable themes.