Fix XSS bug: Properly encode title used in Quick/Bulk Edit, and offer additional sanitization to various fields. Affects users of the Author or Contributor role.

http://www.cvedetails.com/cve/CVE-2011-0700/
http://core.trac.wordpress.org/changeset/17406
http://core.trac.wordpress.org/changeset/17397
http://core.trac.wordpress.org/changeset/17412

This vulnerability affects the following application versions:

  • WordPress 3.0
  • WordPress 3.0.1
  • WordPress 3.0.2
  • WordPress 3.0.3
  • WordPress 3.0.4

Skriv et svar

Din e-mailadresse vil ikke blive publiceret. Krævede felter er markeret med *