Description
WordPress is prone to multiple vulnerabilities, including Denial of Service and information disclosure vulnerabilities. Attackers can exploit these issues to consume memory and bandwidth resources, thus denying service to legitimate users or to gain information that may aid in further attacks. WordPress versions prior to 2.1 are vulnerable.
Remediation
Update to WordPress version 3.6 or latest
References
http://www.securityfocus.com/bid/22220/exploit
http://www.securityfocus.com/archive/1/458003
http://core.trac.wordpress.org/attachment/ticket/4137/exploit.py
Related Vulnerabilities
e107 Permissions, Privileges, and Access Controls Vulnerability (CVE-2008-2020)
WordPress Plugin Login Logout Menu Multiple Cross-Site Scripting Vulnerabilities (1.3.3)
WordPress Plugin Contact Form DB-Elementor Cross-Site Scripting (1.7)
Elgg Exposure of Private Personal Information to an Unauthorized Actor Vulnerability (CVE-2021-3980)