Wordpress Cross Site Scripting Vulnerability Fixed by 4.2.1
Description
A vulnerability has been identified in Wordpress.
A remote attacker could exploit it in order to execute arbitrary Javascript or HTML code by inciting their victim into following a specially crafted link.
This vulnerability stems from a improper filtering of users input in comment fields.
To trigger this vulnerability, the attacker must put a text exceeding 64kb in size (MySQL TEXT type limit size) in the comment field.
A proof of concept is available.
Updated, 04/05/2015:
The wordpress packages provided by Debian Squeeze 6 are vulnerable.
Updated, 07/05/2015:
The de-wordpress, ja-wordpress, ru-wordpress, wordpress, zh-wordpress-zh_CH and zh-wordpress-zh_TW packages provided by FreeBSD are vulnerable.