Multiple Cross-Site Scripting Vulnerabilities in Math Comment Spam Protection Plugin for WordPress
CVE-2008-0204
Currently unrated
Summary
The Math Comment Spam Protection plugin for WordPress has multiple vulnerabilities that allow remote attackers to perform Cross-Site Scripting (XSS) attacks. By exploiting the parameters mcsp_opt_msg_no_answer and mcsp_opt_msg_wrong_answer in 'wp-admin/options-general.php', attackers can inject arbitrary web scripts or HTML, compromising the security of user data and potentially leading to further exploitation of the site.
References
Timeline
Vulnerability published
Vulnerability Reserved