CVE-2006-4028
EPSS 3.7%
Description
Multiple unspecified vulnerabilities in WordPress before 2.0.4 have unknown impact and remote attack vectors. NOTE: due to lack of details, it is not clear how these issues are different from CVE-2006-3389 and CVE-2006-3390, although it is likely that 2.0.4 addresses an unspecified issue related to "Anyone can register" functionality (user registration for guests).
How to fix CVE-2006-4028
To remediate CVE-2006-4028, upgrade the affected package to a fixed version below.
- Debian/wordpress—upgrade to 2.0.4-1 or later
Is CVE-2006-4028 being exploited?
Low — EPSS is 3.7%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 2.0.4-1