WordPress Critical Vulnerability
A cross-site scripting (XSS) vulnerability has been founded in wp-admin/templates.php in WordPress. All the version of WordPress till 2.0.5 are affected. WordPress has fixed this error for WordPress 2.0.6 and released a patch for version 2.0.5.
The Possible Threat
Attacker-supplied HTML and script code would execute in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible. — SecurityFocus.com
If you still do not upgrade your WordPress to version 2.0.6, please do it asap. To get more blogging news, you can subscribe to this blog for FREE.
via LiewCF.com.
This entry was posted on Friday, January 5th, 2007 at 3:39 am and is filed under Blog Tools. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

Leave a Reply