CVE-2009-1030
Wordpress MU < 2.6 - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in the choose_primary_blog function in wp-includes/wpmu-functions.php in WordPress MU (WPMU) before 2.7 allows remote attackers to inject arbitrary web script or HTML via the HTTP Host header.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Juan Galiana Lara · textwebappsphp
https://www.exploit-db.com/exploits/8196
References (6)
Scores
EPSS
0.0178
EPSS Percentile
82.5%
Classification
CWE
CWE-79
Status
published
Affected Products (27)
wordpress/wordpress_mu
< 2.6
wordpress/wordpress_mu
wordpress/wordpress_mu
wordpress/wordpress_mu
wordpress/wordpress_mu
wordpress/wordpress_mu
wordpress/wordpress_mu
wordpress/wordpress_mu
wordpress/wordpress_mu
wordpress/wordpress_mu
wordpress/wordpress_mu
wordpress/wordpress_mu
wordpress/wordpress_mu
wordpress/wordpress_mu
wordpress/wordpress_mu
... and 12 more
Timeline
Published
Mar 20, 2009
Tracked Since
Feb 18, 2026