CVE-2008-0205
Wordpress Math Comment Spam Protection Plugin < 2.1 - XSS
Title source: ruleDescription
Multiple cross-site request forgery (CSRF) vulnerabilities in math-comment-spam-protection.php in the Math Comment Spam Protection 2.1 and earlier plugin for WordPress allow remote attackers to perform actions as administrators via the (1) mcsp_opt_msg_no_answer or (2) mcsp_opt_msg_wrong_answer parameter to wp-admin/options-general.php.
References (4)
Scores
EPSS
0.0040
EPSS Percentile
60.1%
Classification
CWE
CWE-79
Status
draft
Affected Products (1)
wordpress/math_comment_spam_protection_plugin
< 2.1
Timeline
Published
Jan 10, 2008
Tracked Since
Feb 18, 2026