WordPress Vulnerabilities
WordPress <= 5.2.2 - Cross-Site Scripting (XSS) in URL Sanitisation
Description
According to the WordPress release notes:
"Props to Soroush Dalili (@irsdl) from NCC Group for disclosing an issue with URL sanitization that can lead to cross-site scripting (XSS) attacks."
Proof of Concept
Affects WordPress
References
Classification
Type
XSS
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Soroush Dalili (@irsdl) - NCC Group
Submitter
Ryan Dewhurst
Verified
No
WPVDB ID
Timeline
Publicly Published
2019-09-05 (about 7 years ago)
Added
2019-09-05 (about 7 years ago)
Last Updated
2020-09-22 (about 5 years ago)