QID 154103
Date Published: 2021-12-02
QID 154103: WordPress Authenticated Cross Site Scripting Vulnerability (CVE-2021-39201)
WordPress is an open-source blogging tool and content management system based on PHP and MySQL. It has many features including a plug-in architecture and a template system.
The installed version of WordPress CMS allow an authenticated but low-privileged user (like contributor/author) to execute XSS in the editor. This bypasses the restrictions imposed on users who do not have the permission to post "unfiltered_html".
Affected versions:
WordPress 5.0 to 5.7.2
Successful exploitation would lead attackers to inject HTML or JavaScript via a cross-site scripting, which can help the attacker carry out further attacks and obtain sensitive information.
Solution
Customers are advised to upgrade to a fixed version WordPress 5.8 or later versions to remediate this vulnerability.
Vendor References
CVEs related to QID 154103
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| WordPress |
|