http://ar3av.free.fr/faillewordpress.php ( 27 / 05 / 2007 ) versions : 2.2 and previous versions. A site could lead a blog administrator to post a malicious javascript in comments, resulting in an open door to XSS.