WordPress is affected by a critical cross-site scripting vulnerability, which could enable anonymous users to compromise a site.
An attacker could exploit the vulnerability by entering carefully crafted comments, containing program code, on WordPress blog posts and pages. Under default settings comments can be entered by anyone without authentication (login).
Program code injected in comments would be inadvertedly executed in the blog administrator’s web browser when they view the comment. The rogue code could then perform administrative operations by covertly taking over the administror account.
Such operations – demonstrated by our proof of concept exploits – include creating a new administrator account (with a known password), changing the current administrator password, and in the most serious case, executing attacker-supplied PHP code on the server. This grants the attacker operating system level access on the server hosting WordPress.
See https://wordpress.org/news/2014/11/wordpress-4-0-1/ and http://klikki.fi/adv/wordpress.html
This vulnerability affects the following application versions:
- WordPress 2.9
- WordPress 2.9.1
- WordPress 2.9.2
- WordPress 3.0
- WordPress 3.0.1
- WordPress 3.0.2
- WordPress 3.0.3
- WordPress 3.0.4
- WordPress 3.0.5
- WordPress 3.0.6
- WordPress 3.1
- WordPress 3.1.1
- WordPress 3.1.2
- WordPress 3.1.3
- WordPress 3.1.4
- WordPress 3.2
- WordPress 3.2.1
- WordPress 3.3
- WordPress 3.3.1
- WordPress 3.3.2
- WordPress 3.3.3
- WordPress 3.4
- WordPress 3.4.1
- WordPress 3.4.2
- WordPress 3.5
- WordPress 3.5.1
- WordPress 3.5.2
- WordPress 3.6
- WordPress 3.6.1
- WordPress 3.7
- WordPress 3.7.1
- WordPress 3.7.2
- WordPress 3.7.3
- WordPress 3.7.4
- WordPress 3.8
- WordPress 3.8.1
- WordPress 3.8.2
- WordPress 3.8.3
- WordPress 3.8.4
- WordPress 3.9
- WordPress 3.9.1
- WordPress 3.9.2
- WordPress 4.0