CVE-2008-5278

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
28/11/2008
Last modified:
09/04/2025

Description

Cross-site scripting (XSS) vulnerability in the self_link function in in the RSS Feed Generator (wp-includes/feed.php) for WordPress before 2.6.5 allows remote attackers to inject arbitrary web script or HTML via the Host header (HTTP_HOST variable).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* 2.6.3 (including)
cpe:2.3:a:wordpress:wordpress:0.6.2:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:0.6.2:beta_2:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:0.6.2.1:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:0.6.2.1:beta_2:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:0.7:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:0.71:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:0.71-gold:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:0.72:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:0.72:beta1:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:0.72:beta2:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:0.72:rc1:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:0.711:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:1.0:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:1.0-platinum:*:*:*:*:*:*:*