Vulnerabilities > Wordpress > Wordpress > 2.0.1

DATE CVE VULNERABILITY TITLE RISK
2006-03-03 CVE-2006-0985 Cross-Site Scripting vulnerability in WordPress
Multiple cross-site scripting (XSS) vulnerabilities in the "post comment" functionality of WordPress 2.0.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) website, and (3) comment parameters.
network
wordpress
4.3
2005-12-21 CVE-2005-4463 Information Disclosure vulnerability in WordPress
WordPress before 1.5.2 allows remote attackers to obtain sensitive information via a direct request to (1) wp-includes/vars.php, (2) wp-content/plugins/hello.php, (3) wp-admin/upgrade-functions.php, (4) wp-admin/edit-form.php, (5) wp-settings.php, and (6) wp-admin/edit-form-comment.php, which leaks the path in an error message related to undefined functions or failed includes.
network
low complexity
wordpress
5.0