WordPress Vulnerabilities
WordPress <= 5.3 - Authenticated Stored XSS via Block Editor Content
Description
WordPress users with lower privileges (like contributors) can inject JavaScript code in the block editor using a specific payload, which is executed within the dashboard. This can lead to XSS if an admin opens the post in the editor. Execution of this attack does require an authenticated user.
Affects WordPress
References
Classification
Type
XSS
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Nguyen The Duc
Submitter
ducnt
Submitter website
Submitter twitter
Verified
No
WPVDB ID
Timeline
Publicly Published
2019-12-13 (about 6 years ago)
Added
2019-12-13 (about 6 years ago)
Last Updated
2020-05-01 (about 6 years ago)