WordPress.com (2.3.2) is vulnerable to two Cross-Site Scripting vulnerabilities. It is important to note that these only affect WordPress.com blogs.

Proof of concept exploits have been released and there is a danger that an XSS Worm could use this type of vulnerability to compromise thousands of WordPress.com blogs. (See developer verse hosted blogs debate.).

Doz from hackerscenter.com released the advisory. The full disclosure advisory is available and a Video demonstration was also released.

Note (again):These vulnerabilities only affect the Hosting Platform WordPress.com as the download package of WordPress doesn’t include invite.php or users.php file.

Read and Contribute to BlogSec News!

Comments

Matt B. on 10 March, 2008 at 11:28 am #

That’s weird. I would have thought WP.com would run the latest code…


Andrea_R on 10 March, 2008 at 3:14 pm #

What about wordpressMU? It doesn;t contain the invite.php file, but it 8does* contain users.php.

http://trac.mu.wordpress.org/browser/trunk/wp-admin/users.php


Donncha O Caoimh on 10 March, 2008 at 4:31 pm #

Thanks for blogging this. The original blogger never contacted us with that exploit, but it’s fixed now.


DK on 11 March, 2008 at 6:31 pm #

Donncha, glad we could help my man.


[…] VanFossen is also jazzed about WordPress 2.5 coming to WordPress.com, details a security vulnerability for WordPress.com blogs was fixed in less than 10 minutes after initial report, Matt Mullenweg’s report that more […]


[…] VanFossen is also jazzed about WordPress 2.5 coming to WordPress.com, details a security vulnerability for WordPress.com blogs was fixed in less than 10 minutes after initial report, Matt Mullenweg’s report that more […]


Comment
Name:
Email:
Website:
Message: