CVE-2007-3639
Publication date 10 July 2007
Last updated 17 July 2025
Ubuntu priority
Description
WordPress before 2.2.2 allows remote attackers to redirect visitors to other websites and potentially obtain sensitive information via (1) the _wp_http_referer parameter to wp-pass.php, related to the wp_get_referer function in wp-includes/functions.php; and possibly other vectors related to (2) wp-includes/pluggable.php and (3) the wp_nonce_ays function in wp-includes/functions.php.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| wordpress | ||