CVE-2009-1030

Wordpress MU < 2.6 - XSS

Title source: rule

Description

Cross-site scripting (XSS) vulnerability in the choose_primary_blog function in wp-includes/wpmu-functions.php in WordPress MU (WPMU) before 2.7 allows remote attackers to inject arbitrary web script or HTML via the HTTP Host header.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Juan Galiana Lara · textwebappsphp
https://www.exploit-db.com/exploits/8196

Scores

EPSS 0.0178
EPSS Percentile 82.5%

Classification

CWE
CWE-79
Status published

Affected Products (27)

wordpress/wordpress_mu < 2.6
wordpress/wordpress_mu
wordpress/wordpress_mu
wordpress/wordpress_mu
wordpress/wordpress_mu
wordpress/wordpress_mu
wordpress/wordpress_mu
wordpress/wordpress_mu
wordpress/wordpress_mu
wordpress/wordpress_mu
wordpress/wordpress_mu
wordpress/wordpress_mu
wordpress/wordpress_mu
wordpress/wordpress_mu
wordpress/wordpress_mu
... and 12 more

Timeline

Published Mar 20, 2009
Tracked Since Feb 18, 2026