CVE-2007-4893
Wordpress - CSRF
Title source: ruleDescription
wp-admin/admin-functions.php in Wordpress before 2.2.3 and Wordpress multi-user (MU) before 1.2.5a does not properly verify the unfiltered_html privilege, which allows remote attackers to conduct cross-site scripting (XSS) attacks via modified data to (1) post.php or (2) page.php with a no_filter field.
References (9)
Scores
EPSS
0.0155
EPSS Percentile
81.2%
Classification
CWE
CWE-352
Status
draft
Affected Products (31)
wordpress/wordpress
wordpress/wordpress
wordpress/wordpress
wordpress/wordpress
wordpress/wordpress
wordpress/wordpress
wordpress/wordpress
wordpress/wordpress
wordpress/wordpress
wordpress/wordpress
wordpress/wordpress
wordpress/wordpress
wordpress/wordpress
wordpress/wordpress
wordpress/wordpress
... and 16 more
Timeline
Published
Sep 14, 2007
Tracked Since
Feb 18, 2026