發信站NCTU CSIE FreeBSD Server (Tue Mar 6 12:11:19 2007)
轉信站ptt!FreeBSD.csie.NCTU!not-for-mail
If you're logged in into wordpress as an admin, your comments aren't properly sanitized, thus allowing an XSS to be posted. This can be exploited using XSRF techniques.
More info & PoC: http://www.virtuax.be/advisories/Advisory4-20022007.txt