CVE-2007-4104

WP-FeedStats < 2.1 - Cross-Site Scripting via RSS2 Feed Query String

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2007-4104. PoCs published by David Kierznowski.

AI-analyzed exploit summary The exploit describes an HTML-injection vulnerability in WP-FeedStats plugin for WordPress, allowing execution of arbitrary HTML and script code due to insufficient input sanitization. The issue affects versions prior to WP-FeedStats 2.4.

Description

Multiple cross-site scripting (XSS) vulnerabilities in the WP-FeedStats before 2.4 plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, one of which involves an rss2 feed with an invalid or missing blog with an XSS sequence in the query string.

Exploits (1)

exploitdb WRITEUP VERIFIED
by David Kierznowski · textwebappsphp
https://www.exploit-db.com/exploits/30403

The exploit describes an HTML-injection vulnerability in WP-FeedStats plugin for WordPress, allowing execution of arbitrary HTML and script code due to insufficient input sanitization. The issue affects versions prior to WP-FeedStats 2.4.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: WP-FeedStats plugin for WordPress < 2.4
No auth needed
Prerequisites: Access to a vulnerable WordPress installation with WP-FeedStats plugin < 2.4
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Exploit mailing-list x_refsource_fulldisc
http://marc.info/?l=full-disclosure&m=118548811323718&w=2
Exploit, Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/25085
Various Sources x_refsource_misc
http://blogsecurity.net/wordpress/news-260707/
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/37259
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/26249
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/35646
Various Sources x_refsource_misc
http://blogsecurity.net/news/news-130707/

Scores

EPSS 0.0505
EPSS Percentile 91.2%

Details

Status published
Products (1)
wp-feedstats/wordpress_plugin < 2.1
Published Jul 31, 2007
Tracked Since Feb 18, 2026