Unrated severityNVD Advisory· Published Aug 18, 2009· Updated Apr 23, 2026
CVE-2009-2851
CVE-2009-2851
Description
Cross-site scripting (XSS) vulnerability in the administrator interface in WordPress before 2.8.2 allows remote attackers to inject arbitrary web script or HTML via a comment author URL.
Affected products
1- cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*Range: <=2.8.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- wordpress.org/development/2009/07/wordpress-2-8-2/nvdPatchVendor Advisory
- bugs.gentoo.org/show_bug.cginvdIssue TrackingThird Party Advisory
- securitytracker.com/idnvdThird Party AdvisoryVDB Entry
- www.debian.org/security/2009/dsa-1871nvdThird Party Advisory
- www.openwall.com/lists/oss-security/2009/07/21/1nvdMailing ListThird Party Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party Advisory
- www.redhat.com/archives/fedora-package-announce/2009-July/msg01241.htmlnvdMailing ListThird Party Advisory
- www.redhat.com/archives/fedora-package-announce/2009-July/msg01253.htmlnvdMailing ListThird Party Advisory
News mentions
0No linked articles in our index yet.