HTTP: WordPress Comments Stored Cross Site Scripting

This signature detects known Cross Site Scripting attacks against Wordpress. A successful attack may lead to arbitrary code execution.

Extended Description

Cross-site scripting (XSS) vulnerability in wp-includes/wp-db.php in WordPress before 4.2.1 allows remote attackers to inject arbitrary web script or HTML via a long comment that is improperly stored because of limitations on the MySQL TEXT data type.

Affected Products

Wordpress wordpress

Short Name
HTTP:XSS:WORDPRESS-COMMENTS-CE
Severity
Major
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2015-3440 Comments Cross Scripting Site Stored WordPress
Release Date
06/09/2015
Supported Platforms

srx-branch-12.3

srx-branch-19.3

vsrx3bsd-19.2

vsrx3bsd-19.4

srx-branch-19.4

vsrx-19.4

srx-19.4

srx-12.3

vsrx-19.2

srx-19.3

Sigpack Version
3735
False Positive
Unknown
Vendors

Wordpress

Debian

CVSS Score

4.3

Found a potential security threat?