QID 150433
Date Published: 2021-12-04
QID 150433: WordPress Stored Cross Site Scripting Vulnerability (CVE-2021-39202)
WordPress is an open-source blogging tool and content management system based on PHP and MySQL. It has many features including a plug-in architecture and a template system.
In affected versions the widgets editor introduced in WordPress 5.8 beta 1 has improper handling of HTML input in the Custom HTML feature. This leads to stored XSS in the custom HTML widget.
Affected versions:
WordPress 5.8 beta 1 - 5.8 beta 2
Successful exploitation would lead attackers to inject HTML or JavaScript via a cross-site scripting, which can help the attacker carry out further attacks and obtain sensitive information.
Solution
Customers are advised to upgrade to a fixed version WordPress 5.8 or later versions to remediate this vulnerability.
Vendor References
CVEs related to QID 150433
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| WordPress |
|