CVE-2008-0203

Wordpress Cryptographp < 1.2 - XSS

Title source: rule

Description

Multiple cross-site scripting (XSS) vulnerabilities in cryptographp/admin.php in the Cryptographp 1.2 and earlier plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) cryptwidth, (2) cryptheight, (3) bgimg, (4) charR, (5) charG, (6) charB, (7) charclear, (8) tfont, (9) charel, (10) charelc, (11) charelv, (12) charnbmin, (13) charnbmax, (14) charspace, (15) charsizemin, (16) charsizemax, (17) charanglemax, (18) noisepxmin, (19) noisepxmax, (20) noiselinemin, (21) noiselinemax, (22) nbcirclemin, (23) nbcirclemax, or (24) brushsize parameter to wp-admin/options-general.php.

Scores

EPSS 0.0022
EPSS Percentile 44.7%

Classification

CWE
CWE-79
Status draft

Affected Products (1)

wordpress/cryptographp < 1.2

Timeline

Published Jan 10, 2008
Tracked Since Feb 18, 2026