WordPress Vulnerabilities
WordPress < 5.4.2 - Authenticated XSS in Block Editor
Description
Props to Sam Thomas (jazzy2fives) for finding an XSS issue where authenticated users with low privileges are able to add JavaScript to posts in the block editor.
Affects WordPress
References
Classification
Type
XSS
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Sam Thomas (jazzy2fives)
Verified
No
WPVDB ID
Timeline
Publicly Published
2020-06-10 (about 6 years ago)
Added
2020-06-11 (about 6 years ago)
Last Updated
2020-06-18 (about 6 years ago)