{"api_version":"1","generated_at":"2026-07-23T05:39:29+00:00","cve":"CVE-2007-4014","urls":{"html":"https://cve.report/CVE-2007-4014","api":"https://cve.report/api/cve/CVE-2007-4014.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-4014","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-4014"},"summary":{"title":"CVE-2007-4014","description":"Cross-site scripting (XSS) vulnerability in a certain index.php installation script related to the (1) Blix 0.9.1, (2) Blixed 1.0, and (3) BlixKrieg (Blix Krieg) 2.2 themes for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter, possibly a related issue to CVE-2007-2757.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-07-26 01:30:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.osvdb.org/37057","name":"http://www.osvdb.org/37057","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://secunia.com/advisories/26115","name":"http://secunia.com/advisories/26115","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"WordPress BlixKrieg Theme \"s\" Cross-Site Scripting - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/26116","name":"http://secunia.com/advisories/26116","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"WordPress Blixed Theme \"s\" Cross-Site Scripting - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/24954","name":"http://www.securityfocus.com/bid/24954","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"WordPress Multiple Themes S Parameter Cross-Site Scripting Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/26109","name":"http://secunia.com/advisories/26109","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"WordPress Blix Theme Cross-Site Scripting Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35474","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35474","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35473","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35473","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35472","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35472","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/37056","name":"http://www.osvdb.org/37056","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-4014","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-4014","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"4014","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"wordpress","cpe5":"blix","cpe6":"0.9.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"4014","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"wordpress","cpe5":"blixed","cpe6":"1.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"4014","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"wordpress","cpe5":"blixkrieg","cpe6":"2.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T14:37:05.952Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"37056","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/37056"},{"name":"blixkrieg-wordpress-index-xss(35474)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35474"},{"name":"26109","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/26109"},{"name":"bllix-wordpress-index-xss(35472)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35472"},{"name":"26115","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/26115"},{"name":"24954","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/24954"},{"name":"37057","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/37057"},{"name":"26116","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/26116"},{"name":"blixed-wordpress-index-xss(35473)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35473"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-07-18T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in a certain index.php installation script related to the (1) Blix 0.9.1, (2) Blixed 1.0, and (3) BlixKrieg (Blix Krieg) 2.2 themes for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter, possibly a related issue to CVE-2007-2757.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-28T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"37056","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/37056"},{"name":"blixkrieg-wordpress-index-xss(35474)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35474"},{"name":"26109","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/26109"},{"name":"bllix-wordpress-index-xss(35472)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35472"},{"name":"26115","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/26115"},{"name":"24954","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/24954"},{"name":"37057","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/37057"},{"name":"26116","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/26116"},{"name":"blixed-wordpress-index-xss(35473)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35473"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-4014","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in a certain index.php installation script related to the (1) Blix 0.9.1, (2) Blixed 1.0, and (3) BlixKrieg (Blix Krieg) 2.2 themes for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter, possibly a related issue to CVE-2007-2757.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"37056","refsource":"OSVDB","url":"http://www.osvdb.org/37056"},{"name":"blixkrieg-wordpress-index-xss(35474)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35474"},{"name":"26109","refsource":"SECUNIA","url":"http://secunia.com/advisories/26109"},{"name":"bllix-wordpress-index-xss(35472)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35472"},{"name":"26115","refsource":"SECUNIA","url":"http://secunia.com/advisories/26115"},{"name":"24954","refsource":"BID","url":"http://www.securityfocus.com/bid/24954"},{"name":"37057","refsource":"OSVDB","url":"http://www.osvdb.org/37057"},{"name":"26116","refsource":"SECUNIA","url":"http://secunia.com/advisories/26116"},{"name":"blixed-wordpress-index-xss(35473)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35473"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-4014","datePublished":"2007-07-26T01:00:00.000Z","dateReserved":"2007-07-25T00:00:00.000Z","dateUpdated":"2024-08-07T14:37:05.952Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-07-26 01:30:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:wordpress:blix:0.9.1:*:*:*:*:*:*:*","matchCriteriaId":"0D18C857-87A8-4470-8370-5F3F59508EAC"},{"vulnerable":true,"criteria":"cpe:2.3:a:wordpress:blixed:1.0:*:*:*:*:*:*:*","matchCriteriaId":"2F2F33C6-C192-46BE-A415-AED38E93262D"},{"vulnerable":true,"criteria":"cpe:2.3:a:wordpress:blixkrieg:2.2:*:*:*:*:*:*:*","matchCriteriaId":"6081585B-7845-4688-90EF-5DE2C3E1975B"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"4014","Ordinal":"1","Title":"CVE-2007-4014","CVE":"CVE-2007-4014","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"4014","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in a certain index.php installation script related to the (1) Blix 0.9.1, (2) Blixed 1.0, and (3) BlixKrieg (Blix Krieg) 2.2 themes for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter, possibly a related issue to CVE-2007-2757.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.","Type":"Description","Title":"CVE-2007-4014"},{"CveYear":"2007","CveId":"4014","Ordinal":"2","NoteData":"2007-07-25","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"4014","Ordinal":"3","NoteData":"2017-07-28","Type":"Other","Title":"Modified"}]}}}