WordPress: HTTP response splitting and XSS vulnerabilities — GLSA 200410-12 WordPress contains HTTP response splitting and cross-site scripting vulnerabilities. Affected packages Package www-apps/wordpress on all architectures Affected versions < 1.2.2 Unaffected versions >= 1.2.2 Background WordPress is a PHP and MySQL based content management and publishing system. Description Due to the lack of input validation in the administration panel scripts, WordPress is vulnerable to HTTP response splitting and cross-site scripting attacks. Impact A malicious user could inject arbitrary response data, leading to content spoofing, web cache poisoning and other cross-site scripting or HTTP response splitting attacks. This could result in compromising the victim's data or browser. Workaround There is no known workaround at this time. Resolution All WordPress users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=www-apps/wordpress-1.2.2" References WordPress 1.2.2 Release Notes CVE-2004-1584