Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2008-1304Cross-site Scripting in Wordpress

Severity
4.3MEDIUMNVD
EPSS
3.1%
top 13.21%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedMar 12
Latest updateMay 1

Description

Multiple cross-site scripting (XSS) vulnerabilities in WordPress 2.3.2 allow remote attackers to inject arbitrary web script or HTML via the (1) inviteemail parameter in an invite action to wp-admin/users.php and the (2) to parameter in a sent action to wp-admin/invites.php.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages2 packages

🔴Vulnerability Details

1
GHSA
GHSA-qjrj-cvjq-fxjr: Multiple cross-site scripting (XSS) vulnerabilities in WordPress 22022-05-01

💥Exploits & PoCs

2
Exploit-DB
WordPress Core 2.3.2 - '/wp-admin/invites.php?to' Cross-Site Scripting2008-03-07
Exploit-DB
WordPress Core 2.3.2 - '/wp-admin/users.php?inviteemail' Cross-Site Scripting2008-03-07

📋Vendor Advisories

2
Red Hat
wordpress: multiple XSS issues in invite action2008-03-07
Debian
CVE-2008-1304: wordpress - Multiple cross-site scripting (XSS) vulnerabilities in WordPress 2.3.2 allow rem...2008

💬Community

1
Bugzilla
CVE-2008-1304 wordpress: multiple XSS issues in invite action2008-03-17
CVE-2008-1304 — Cross-site Scripting in Wordpress | cvebase