(#Several vulnerabilities have been identified in the following themes for Wordpress:#- MoneyTheme: cross-site scripting in the "src" parameter of the "timthumb.php" page and arbitrary file upload#- Salutation Responsive WordPress + BuddyPress: authenticated stored cross-site scripting.##Proofs of concept are available.)
Vulnerable Products
Vulnerable Software: WordPress (WordPress) -
Solution
Version 3.0.16 of Salutation Responsive WordPress fixes its vulnerability.