Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2006-0733Cross-site Scripting in Wordpress

5 documents5 sources
Severity
2.6LOWNVD
EPSS
0.8%
top 25.38%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedFeb 16
Latest updateMay 1

Description

Cross-site scripting (XSS) vulnerability in WordPress 2.0.0 allows remote attackers to inject arbitrary web script or HTML via scriptable attributes such as (1) onfocus and (2) onblur in the "author's website" field. NOTE: followup comments to the researcher's web log suggest that this issue is only exploitable by the same user who injects the XSS, so this might not be a vulnerability

CVSS vector

AV:N/AC:H/C:N/I:P/A:NExploitability: 4.9 | Impact: 2.9

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-pwhv-j4q5-f4g2: ** DISPUTED ** Cross-site scripting (XSS) vulnerability in WordPress 22022-05-01
OSV
CVE-2006-0733: Cross-site scripting (XSS) vulnerability in WordPress 22006-02-16

💥Exploits & PoCs

1
Exploit-DB
WordPress Core 2.0 - Comment Post HTML Injection2006-02-15

📋Vendor Advisories

1
Debian
CVE-2006-0733: wordpress - Cross-site scripting (XSS) vulnerability in WordPress 2.0.0 allows remote attack...2006
CVE-2006-0733 — Cross-site Scripting in Wordpress | cvebase