QID 154111
Date Published: 2022-05-20
QID 154111: WordPress Stored Cross-Site Scripting (XSS) Vulnerability (CVE-2019-20042)
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database.
The function wp_targeted_link_rel() can be used in a particular way to result in a Stored Cross-Site Scripting (XSS) vulnerability.
Affected Versions:
WordPress versions prior to 5.3.1
QID Detection Logic:
This QID checks for vulnerable version of WordPress installed on the target.
Successful exploitation could allow an attacker to execute arbitrary JavaScript code in the context of the interface or allow the attacker to access sensitive, browser-based information.
Solution
Upgrade the WordPress to new version.
Vendor References
CVEs related to QID 154111
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| WordPress |
|