{"api_version":"1","generated_at":"2026-07-23T06:06:35+00:00","cve":"CVE-2007-4104","urls":{"html":"https://cve.report/CVE-2007-4104","api":"https://cve.report/api/cve/CVE-2007-4104.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-4104","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-4104"},"summary":{"title":"CVE-2007-4104","description":"Multiple cross-site scripting (XSS) vulnerabilities in the WP-FeedStats before 2.4 plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, one of which involves an rss2 feed with an invalid or missing blog with an XSS sequence in the query string.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-07-31 10:17:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://osvdb.org/37259","name":"http://osvdb.org/37259","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35646","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35646","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://blogsecurity.net/news/news-130707/","name":"http://blogsecurity.net/news/news-130707/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"404"},{"url":"http://marc.info/?l=full-disclosure&m=118548811323718&w=2","name":"http://marc.info/?l=full-disclosure&m=118548811323718&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"'[Full-disclosure] WordPress wp-feedstats persistent XSS' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://bueltge.de/plugin-wp-feedstats-in-neuer-version/481/","name":"http://bueltge.de/plugin-wp-feedstats-in-neuer-version/481/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Plugin WP-FeedStats in neuer Version |  bueltge.de [by:ltge.de]","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://blogsecurity.net/wordpress/news-260707/","name":"http://blogsecurity.net/wordpress/news-260707/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"BlogSecurity  » Blog Archive   » wp-feedstats persistent XSS","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/25085","name":"http://www.securityfocus.com/bid/25085","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Patch"],"title":"WordPress WP-FeedStats HTML Injection Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/26249","name":"http://secunia.com/advisories/26249","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"WP-FeedStats Plugin for WordPress Script Insertion Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-4104","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-4104","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"4104","vulnerable":"1","versionEndIncluding":"2.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"wp-feedstats","cpe5":"wordpress_plugin","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T14:46:38.609Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20070726 WordPress wp-feedstats persistent XSS","tags":["mailing-list","x_refsource_FULLDISC","x_transferred"],"url":"http://marc.info/?l=full-disclosure&m=118548811323718&w=2"},{"name":"25085","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/25085"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://blogsecurity.net/wordpress/news-260707/"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://bueltge.de/plugin-wp-feedstats-in-neuer-version/481/"},{"name":"37259","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/37259"},{"name":"26249","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/26249"},{"name":"wordpress-wpfeedstats-xss(35646)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35646"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://blogsecurity.net/news/news-130707/"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-07-26T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple cross-site scripting (XSS) vulnerabilities in the WP-FeedStats before 2.4 plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, one of which involves an rss2 feed with an invalid or missing blog with an XSS sequence in the query string."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-28T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"20070726 WordPress wp-feedstats persistent XSS","tags":["mailing-list","x_refsource_FULLDISC"],"url":"http://marc.info/?l=full-disclosure&m=118548811323718&w=2"},{"name":"25085","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/25085"},{"tags":["x_refsource_MISC"],"url":"http://blogsecurity.net/wordpress/news-260707/"},{"tags":["x_refsource_CONFIRM"],"url":"http://bueltge.de/plugin-wp-feedstats-in-neuer-version/481/"},{"name":"37259","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/37259"},{"name":"26249","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/26249"},{"name":"wordpress-wpfeedstats-xss(35646)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35646"},{"tags":["x_refsource_MISC"],"url":"http://blogsecurity.net/news/news-130707/"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-4104","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple cross-site scripting (XSS) vulnerabilities in the WP-FeedStats before 2.4 plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, one of which involves an rss2 feed with an invalid or missing blog with an XSS sequence in the query string."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20070726 WordPress wp-feedstats persistent XSS","refsource":"FULLDISC","url":"http://marc.info/?l=full-disclosure&m=118548811323718&w=2"},{"name":"25085","refsource":"BID","url":"http://www.securityfocus.com/bid/25085"},{"name":"http://blogsecurity.net/wordpress/news-260707/","refsource":"MISC","url":"http://blogsecurity.net/wordpress/news-260707/"},{"name":"http://bueltge.de/plugin-wp-feedstats-in-neuer-version/481/","refsource":"CONFIRM","url":"http://bueltge.de/plugin-wp-feedstats-in-neuer-version/481/"},{"name":"37259","refsource":"OSVDB","url":"http://osvdb.org/37259"},{"name":"26249","refsource":"SECUNIA","url":"http://secunia.com/advisories/26249"},{"name":"wordpress-wpfeedstats-xss(35646)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35646"},{"name":"http://blogsecurity.net/news/news-130707/","refsource":"MISC","url":"http://blogsecurity.net/news/news-130707/"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-4104","datePublished":"2007-07-31T10:00:00.000Z","dateReserved":"2007-07-31T00:00:00.000Z","dateUpdated":"2024-08-07T14:46:38.609Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-07-31 10:17:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:wp-feedstats:wordpress_plugin:*:*:*:*:*:*:*:*","versionEndIncluding":"2.1","matchCriteriaId":"80E09F20-0427-4706-89B4-CD0B1BD65859"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"4104","Ordinal":"1","Title":"CVE-2007-4104","CVE":"CVE-2007-4104","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"4104","Ordinal":"1","NoteData":"Multiple cross-site scripting (XSS) vulnerabilities in the WP-FeedStats before 2.4 plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, one of which involves an rss2 feed with an invalid or missing blog with an XSS sequence in the query string.","Type":"Description","Title":"CVE-2007-4104"},{"CveYear":"2007","CveId":"4104","Ordinal":"2","NoteData":"2007-07-31","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"4104","Ordinal":"3","NoteData":"2017-07-28","Type":"Other","Title":"Modified"}]}}}