QID 150433

Date Published: 2021-12-04

QID 150433: WordPress Stored Cross Site Scripting Vulnerability (CVE-2021-39202)

WordPress is an open-source blogging tool and content management system based on PHP and MySQL. It has many features including a plug-in architecture and a template system.

In affected versions the widgets editor introduced in WordPress 5.8 beta 1 has improper handling of HTML input in the Custom HTML feature. This leads to stored XSS in the custom HTML widget.

Affected versions:
WordPress 5.8 beta 1 - 5.8 beta 2

Successful exploitation would lead attackers to inject HTML or JavaScript via a cross-site scripting, which can help the attacker carry out further attacks and obtain sensitive information.

  • CVSS V3 rated as Medium - 5.4 severity.
  • CVSS V2 rated as Medium - 3.5 severity.
  • Solution
    Customers are advised to upgrade to a fixed version WordPress 5.8 or later versions to remediate this vulnerability.

    CVEs related to QID 150433

    Software Advisories
    Advisory ID Software Component Link
    WordPress URL Logo wordpress.org/download/releases/