{"api_version":"1","generated_at":"2026-07-23T05:42:27+00:00","cve":"CVE-2008-4733","urls":{"html":"https://cve.report/CVE-2008-4733","api":"https://cve.report/api/cve/CVE-2008-4733.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-4733","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-4733"},"summary":{"title":"CVE-2008-4733","description":"Cross-site scripting (XSS) vulnerability in wpcommentremix.php in WP Comment Remix plugin before 1.4.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the (1) replytotext, (2) quotetext, (3) originallypostedby, (4) sep, (5) maxtags, (6) tagsep, (7) tagheadersep, (8) taglabel, and (9) tagheaderlabel parameters.","state":"PUBLISHED","assigner":"mitre","published_at":"2008-10-24 10:30:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://chxsecurity.org/advisories/adv-3-full.txt","name":"http://chxsecurity.org/advisories/adv-3-full.txt","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/plain","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/497313/100/0/threaded","name":"http://www.securityfocus.com/archive/1/497313/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securityreason.com/securityalert/4492","name":"http://securityreason.com/securityalert/4492","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"WP Comment Remix 1.4.3 Multiple Vulnerabilities - CXSecurity.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/32253","name":"http://secunia.com/advisories/32253","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"WordPress WP Comment Remix Plugin Multiple Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/31750","name":"http://www.securityfocus.com/bid/31750","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"WP Comment Remix 1.4.3 SQL Injection and HTML Injection Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/45861","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/45861","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-4733","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-4733","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"4733","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"pressography","cpe5":"wp_comment_remix_plugin","cpe6":"1.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"4733","vulnerable":"1","versionEndIncluding":"1.4.3","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"pressography","cpe5":"wp_comment_remix_plugin","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"4733","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"wordpress","cpe5":"wordpress","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T10:24:21.039Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"32253","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/32253"},{"name":"20081014 WP Comment Remix 1.4.3 Multiple Vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/497313/100/0/threaded"},{"name":"31750","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/31750"},{"name":"wpcommentremix-wpcommentremix-xss(45861)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/45861"},{"name":"4492","tags":["third-party-advisory","x_refsource_SREASON","x_transferred"],"url":"http://securityreason.com/securityalert/4492"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://chxsecurity.org/advisories/adv-3-full.txt"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2008-10-13T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in wpcommentremix.php in WP Comment Remix plugin before 1.4.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the (1) replytotext, (2) quotetext, (3) originallypostedby, (4) sep, (5) maxtags, (6) tagsep, (7) tagheadersep, (8) taglabel, and (9) tagheaderlabel parameters."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-11T19:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"32253","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/32253"},{"name":"20081014 WP Comment Remix 1.4.3 Multiple Vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/497313/100/0/threaded"},{"name":"31750","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/31750"},{"name":"wpcommentremix-wpcommentremix-xss(45861)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/45861"},{"name":"4492","tags":["third-party-advisory","x_refsource_SREASON"],"url":"http://securityreason.com/securityalert/4492"},{"tags":["x_refsource_MISC"],"url":"http://chxsecurity.org/advisories/adv-3-full.txt"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2008-4733","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in wpcommentremix.php in WP Comment Remix plugin before 1.4.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the (1) replytotext, (2) quotetext, (3) originallypostedby, (4) sep, (5) maxtags, (6) tagsep, (7) tagheadersep, (8) taglabel, and (9) tagheaderlabel parameters."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"32253","refsource":"SECUNIA","url":"http://secunia.com/advisories/32253"},{"name":"20081014 WP Comment Remix 1.4.3 Multiple Vulnerabilities","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/497313/100/0/threaded"},{"name":"31750","refsource":"BID","url":"http://www.securityfocus.com/bid/31750"},{"name":"wpcommentremix-wpcommentremix-xss(45861)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/45861"},{"name":"4492","refsource":"SREASON","url":"http://securityreason.com/securityalert/4492"},{"name":"http://chxsecurity.org/advisories/adv-3-full.txt","refsource":"MISC","url":"http://chxsecurity.org/advisories/adv-3-full.txt"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2008-4733","datePublished":"2008-10-24T10:00:00.000Z","dateReserved":"2008-10-24T00:00:00.000Z","dateUpdated":"2024-08-07T10:24:21.039Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2008-10-24 10:30:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:pressography:wp_comment_remix_plugin:*:*:*:*:*:*:*:*","versionEndIncluding":"1.4.3","matchCriteriaId":"315D7262-1A75-4004-980F-DF7A4DEE3C5C"},{"vulnerable":true,"criteria":"cpe:2.3:a:pressography:wp_comment_remix_plugin:1.4:*:*:*:*:*:*:*","matchCriteriaId":"D6CF79C4-B5D3-4C24-84DB-51455C622A8C"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*","matchCriteriaId":"847DA578-4655-477E-8A6F-99FBE738E4F9"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"4733","Ordinal":"1","Title":"CVE-2008-4733","CVE":"CVE-2008-4733","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"4733","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in wpcommentremix.php in WP Comment Remix plugin before 1.4.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the (1) replytotext, (2) quotetext, (3) originallypostedby, (4) sep, (5) maxtags, (6) tagsep, (7) tagheadersep, (8) taglabel, and (9) tagheaderlabel parameters.","Type":"Description","Title":"CVE-2008-4733"},{"CveYear":"2008","CveId":"4733","Ordinal":"2","NoteData":"2008-10-24","Type":"Other","Title":"Published"},{"CveYear":"2008","CveId":"4733","Ordinal":"3","NoteData":"2018-10-11","Type":"Other","Title":"Modified"}]}}}