CVE-2019-20042
Summary
| CVE | CVE-2019-20042 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-12-27 08:15:00 UTC |
| Updated | 2023-01-19 03:13:00 UTC |
| Description | In wp-includes/formatting.php in WordPress 3.7 to 5.3.0, the function wp_targeted_link_rel() can be used in a particular way to result in a stored cross-site scripting (XSS) vulnerability. This has been patched in WordPress 5.3.1, along with all the previous WordPress versions from 3.7 to 5.3 via a minor release. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| WordPress <= 5.3 - Stored XSS via Crafted Links |
MISC |
wpvulndb.com |
Release Notes, Third Party Advisory |
| Debian -- Security Information -- DSA-4677-1 wordpress |
DEBIAN |
www.debian.org |
|
| HackerOne |
MISC |
hackerone.com |
|
| Changeset 46894 for trunk – WordPress Trac |
MISC |
core.trac.wordpress.org |
Patch |
| Stored cross-site scripting (XSS) through 'wp_targeted_link_rel' · Advisory · WordPress/wordpress-develop · GitHub |
CONFIRM |
github.com |
|
| Filter Vulnerabilities |
MISC |
blog.ripstech.com |
Not Applicable |
| News – WordPress 5.3.1 Security and Maintenance Release – WordPress.org |
MISC |
wordpress.org |
Release Notes, Vendor Advisory |
| Debian -- Security Information -- DSA-4599-1 wordpress |
DEBIAN |
www.debian.org |
|
| Prevent stored XSS through wp_targeted_link_rel(). · WordPress/wordpress-develop@1f7f3f1 · GitHub |
MISC |
github.com |
Patch |
| Bugtraq: [SECURITY] [DSA 4599-1] wordpress security update |
BUGTRAQ |
seclists.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 154111 WordPress Stored Cross-Site Scripting (XSS) Vulnerability (CVE-2019-20042)