CVE-2007-4893

Source
https://cve.org/CVERecord?id=CVE-2007-4893
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2007-4893.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2007-4893
Downstream
Published
2007-09-14T18:17:00Z
Modified
2026-04-10T03:39:12.617425Z
Summary
[none]
Details

wp-admin/admin-functions.php in Wordpress before 2.2.3 and Wordpress multi-user (MU) before 1.2.5a does not properly verify the unfilteredhtml privilege, which allows remote attackers to conduct cross-site scripting (XSS) attacks via modified data to (1) post.php or (2) page.php with a nofilter field.

References

Affected packages