First published: Thu Jan 10 2008(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in captcha\captcha.php in the Captcha! 2.5d and earlier plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) captcha_ttffolder, (2) captcha_numchars, (3) captcha_ttfrange, or (4) captcha_secret parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Wordpress Captcha | <=2.5d |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-0206 is classified as a medium severity vulnerability due to its ability to permit cross-site scripting attacks.
To fix CVE-2008-0206, update the Captcha! plugin to a version greater than 2.5d that addresses these vulnerabilities.
CVE-2008-0206 can be exploited to perform cross-site scripting attacks, allowing attackers to inject web scripts or HTML.
CVE-2008-0206 affects the Captcha! plugin versions 2.5d and earlier.
The vulnerability in CVE-2008-0206 is found in the captcha.php file of the Captcha! plugin for WordPress.