CVE-2011-4899: XSS
DISPUTED wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier does not ensure that the specified MySQL database service is appropriate, which allows remote attackers to configure an arbitrary database via the dbhost and dbname parameters, and subsequently conduct static code injection and cross-site scripting (XSS) attacks via (1) an HTTP request or (2) a MySQL query. NOTE: the vendor disputes the significance of this issue; however, remote code execution makes the issue important in many realistic environments.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4899?
CVE-2011-4899 has a high severity due to the potential for unauthorized access to database configuration.
How do I fix CVE-2011-4899?
To fix CVE-2011-4899, upgrade to WordPress version 3.3.2 or later that addresses this vulnerability.
What impact does CVE-2011-4899 have on WordPress installations?
CVE-2011-4899 allows remote attackers to potentially configure an arbitrary database, posing a significant security risk.
Is my WordPress site affected by CVE-2011-4899?
If your WordPress version is 3.3.1 or earlier, your site is affected by CVE-2011-4899.
What versions of WordPress are vulnerable to CVE-2011-4899?
All versions of WordPress up to and including 3.3.1 are vulnerable to CVE-2011-4899.