WordPress Vulnerabilities
WP < 7.0.3 - Contributor+ Stored XSS in Quick Edits
Description
WordPress does not properly escape user display names in some cases, which could allow users with a role of Contributor and above to perform Stored Cross-Site Scripting attacks against higher privileged users viewing the affected admin screens.
Affects WordPress
References
Classification
Type
XSS
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Naveen S and Ajmal Moochingal
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-08-06 (about 1 month ago)
Added
2026-08-06 (about 1 month ago)
Last Updated
2026-08-06 (about 1 month ago)