Unrated severityNVD Advisory· Published Sep 26, 2007· Updated Apr 23, 2026
CVE-2007-5105
CVE-2007-5105
Description
Cross-site scripting (XSS) vulnerability in wp-register.php in WordPress 2.0 and 2.0.1 allows remote attackers to inject arbitrary web script or HTML via the user_email parameter.
Affected products
2cpe:2.3:a:wordpress:wordpress:2.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:wordpress:wordpress:2.0:*:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:2.0.1:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- blogsecurity.net/wordpress/2-vanilla-xss-on-wordpress-wp-registerphp/nvd
- securityreason.com/securityalert/3175nvd
- www.securityfocus.com/archive/1/480327/100/0/threadednvd
- www.securityfocus.com/bid/25769nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/36742nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/36743nvd
News mentions
0No linked articles in our index yet.