vendor:
Wordpress
by:
5.5
CVSS
MEDIUM
Multiple
CWE
Product Name: Wordpress
Affected Version From: 2.9.2004
Affected Version To: 2.9.2004
Patch Exists: NO
Related CWE:
CPE: a:gazette_edition:wordpress:2.9.4
Platforms Tested:
Multiple vulnerabilities in Gazette Edition for WordPress
The Gazette Edition for Wordpress is prone to multiple security vulnerabilities. These vulnerabilities include multiple denial-of-service vulnerabilities, a cross-site scripting vulnerability, and an information-disclosure vulnerability. Exploiting these issues could allow an attacker to deny service to legitimate users, gain access to sensitive information, execute arbitrary script code, or steal cookie-based authentication credentials. Other attacks may also be possible.
Mitigation:
Upgrade to Gazette Edition for Wordpress version 2.9.5 or later to address these vulnerabilities.