Multiple Cross-Site Scripting Vulnerabilities in Math Comment Spam Protection Plugin for WordPress
CVE-2008-0204

Currently unrated

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
10 January 2008

Summary

The Math Comment Spam Protection plugin for WordPress has multiple vulnerabilities that allow remote attackers to perform Cross-Site Scripting (XSS) attacks. By exploiting the parameters mcsp_opt_msg_no_answer and mcsp_opt_msg_wrong_answer in 'wp-admin/options-general.php', attackers can inject arbitrary web scripts or HTML, compromising the security of user data and potentially leading to further exploitation of the site.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.