WordPress Multiple Themes S Parameter Cross-Site Scripting Vulnerability

Multiple themes for WordPress are prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.

An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

These themes for WordPress are reported vulnerable:

BlixKrieg 2.2
Blixed 1.0
Blix 0.9.1


 

Privacy Statement
Copyright 2010, SecurityFocus