CVE-2008-0664Wordpress vulnerability

CWE-2646 documents6 sources
Severity
6.4MEDIUMNVD
EPSS
6.8%
top 8.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 8
Latest updateMay 1

Description

The XML-RPC implementation (xmlrpc.php) in WordPress before 2.3.3, when registration is enabled, allows remote attackers to edit posts of other blog users via unknown vectors.

CVSS vector

AV:N/AC:L/C:P/I:P/A:NExploitability: 10.0 | Impact: 4.9

Affected Packages3 packages

debiandebian/wordpress< wordpress 2.3.3-1 (bookworm)
Debianwordpress/wordpress< 2.3.3-1+3
NVDwordpress/wordpress38 versions+37

Patches

🔴Vulnerability Details

2
GHSA
GHSA-4v2q-r7pp-6g8x: The XML-RPC implementation (xmlrpc2022-05-01
OSV
CVE-2008-0664: The XML-RPC implementation (xmlrpc2008-02-08

📋Vendor Advisories

2
Red Hat
wordpress: XML-RPC interface vulnerability2008-02-05
Debian
CVE-2008-0664: wordpress - The XML-RPC implementation (xmlrpc.php) in WordPress before 2.3.3, when registra...2008

💬Community

1
Bugzilla
CVE-2008-0664 wordpress: XML-RPC interface vulnerability2008-02-05
CVE-2008-0664 — Debian Wordpress vulnerability | cvebase