Input validation vulnerability in WordPress MU 2.7

There is a security vulnerability in WordPress MU (WPMU) before version 2.7 that allows attackers to inject malicious code (like web scripts or HTML) into a website using the HTTP Host header. This vulnerability is called Cross-site Scripting (XSS).

Detected in:

WordPress MU fixed vulnerable versions: >= * < 2.7

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.