CVE-2010-4536
published 2011-01-03CVE-2010-4536: Multiple cross-site scripting (XSS) vulnerabilities in KSES, as used in WordPress before 3.0.4, allow remote attackers to inject arbitrary web script or HTML…
PriorityP418medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
3.45%
87.8th percentile
Multiple cross-site scripting (XSS) vulnerabilities in KSES, as used in WordPress before 3.0.4, allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) the & (ampersand) character, (2) the case of an attribute name, (3) a padded entity, and (4) an entity that is not in normalized form.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wordpress | < wordpress 3.0.4+dfsg-1 (bookworm) | wordpress 3.0.4+dfsg-1 (bookworm) |
| wordpress | wordpress | <= 3.0.3 | — |
| wordpress | wordpress | >= 0 < 3.0.4+dfsg-1 | 3.0.4+dfsg-1 |
| wordpress | wordpress | >= 0 < 3.0.4+dfsg-1 | 3.0.4+dfsg-1 |
| wordpress | wordpress | >= 0 < 3.0.4+dfsg-1 | 3.0.4+dfsg-1 |
| wordpress | wordpress | >= 0 < 3.0.4+dfsg-1 | 3.0.4+dfsg-1 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-x7cw-w76m-9h8q: Multiple cross-site scripting (XSS) vulnerabilities in KSES, as used in WordPress before 3
ghsa_unreviewed·2022-05-17
CVE-2010-4536 [MEDIUM] CWE-79 GHSA-x7cw-w76m-9h8q: Multiple cross-site scripting (XSS) vulnerabilities in KSES, as used in WordPress before 3
Multiple cross-site scripting (XSS) vulnerabilities in KSES, as used in WordPress before 3.0.4, allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) the & (ampersand) character, (2) the case of an attribute name, (3) a padded entity, and (4) an entity that is not in normalized form.
OSV
CVE-2010-4536: Multiple cross-site scripting (XSS) vulnerabilities in KSES, as used in WordPress before 3
osv·2011-01-03·CVSS 4.3
CVE-2010-4536 [MEDIUM] CVE-2010-4536: Multiple cross-site scripting (XSS) vulnerabilities in KSES, as used in WordPress before 3
Multiple cross-site scripting (XSS) vulnerabilities in KSES, as used in WordPress before 3.0.4, allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) the & (ampersand) character, (2) the case of an attribute name, (3) a padded entity, and (4) an entity that is not in normalized form.
Debian
CVE-2010-4536: wordpress - Multiple cross-site scripting (XSS) vulnerabilities in KSES, as used in WordPres...
vendor_debian·2010·CVSS 4.3
CVE-2010-4536 [MEDIUM] CVE-2010-4536: wordpress - Multiple cross-site scripting (XSS) vulnerabilities in KSES, as used in WordPres...
Multiple cross-site scripting (XSS) vulnerabilities in KSES, as used in WordPress before 3.0.4, allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) the & (ampersand) character, (2) the case of an attribute name, (3) a padded entity, and (4) an entity that is not in normalized form.
Scope: local
bookworm: resolved (fixed in 3.0.4+dfsg-1)
bullseye: resolved (fixed in 3.0.4+dfsg-1)
forky: resolved (fixed in 3.0.4+dfsg-1)
sid: resolved (fixed in 3.0.4+dfsg-1)
trixie: resolved (fixed in 3.0.4+dfsg-1)
No detection rules found.
No public exploits indexed.
http://core.trac.wordpress.org/changeset/17172/branches/3.0http://lists.fedoraproject.org/pipermail/package-announce/2011-January/053289.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-January/053293.htmlhttp://secunia.com/advisories/42755http://secunia.com/advisories/43000http://wordpress.org/news/2010/12/3-0-4-update/http://www.openwall.com/lists/oss-security/2010/12/30/1http://www.securityfocus.com/bid/45620http://www.vupen.com/english/advisories/2010/3335http://www.vupen.com/english/advisories/2011/0167http://core.trac.wordpress.org/changeset/17172/branches/3.0http://lists.fedoraproject.org/pipermail/package-announce/2011-January/053289.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-January/053293.htmlhttp://secunia.com/advisories/42755http://secunia.com/advisories/43000http://wordpress.org/news/2010/12/3-0-4-update/http://www.openwall.com/lists/oss-security/2010/12/30/1http://www.securityfocus.com/bid/45620http://www.vupen.com/english/advisories/2010/3335http://www.vupen.com/english/advisories/2011/0167
2011-01-03
Published