WordPress Vulnerabilities
WordPress < 5.4.2 - Authenticated Stored XSS via Theme Upload
Description
An authenticated user could upload a purposely broken theme and then change the theme's directory name with a Cross-Site Scripting (XSS) payload. When WordPress warns the user about the broken theme, the XSS payload is then executed.
This vulnerability would be difficult to exploit by an attacker in the real world, as the attacker would need to be able to upload themes and be able to modify directory names on the server.
One possible attack scenario is an attacker social engineering a victim to perform these actions, which is very unlikely.
Affects WordPress
References
Classification
Type
XSS
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Nrimo Ing Pandum
Verified
No
WPVDB ID
Timeline
Publicly Published
2020-06-11 (about 5 years ago)
Added
2020-06-11 (about 5 years ago)
Last Updated
2020-08-28 (about 5 years ago)