CVE-2007-2627

Publication date 11 May 2007

Last updated 17 July 2025


Ubuntu priority

Description

Cross-site scripting (XSS) vulnerability in sidebar.php in WordPress, when custom 404 pages that call get_sidebar are used, allows remote attackers to inject arbitrary web script or HTML via the query string (PHP_SELF), a different vulnerability than CVE-2007-1622.

Status

Package Ubuntu Release Status
wordpress 9.10 karmic
Not affected
9.04 jaunty
Not affected
8.10 intrepid
Not affected
8.04 LTS hardy
Not affected
7.10 gutsy
Not affected
7.04 feisty Ignored end of life, was needs-triage
6.10 edgy Ignored end of life, was needs-triage
6.06 LTS dapper Ignored end of life