Cross Site Scripting Vulnerability Juan Galiana Lara has released details regarding a vulnerability that affects WordPress MU versions < 2.7. Version 2.7 is NOT affected according to the advisory. So if you have upgraded to 2.7 you can ignore this advisory. Vulnerability Details WordPress MU prior to version 2.7 fails to sanitize the Host header correctly in choose_primary_blog function [...]