WordPress Vulnerabilities

WordPress < 5.4.1 - Cross-Site Scripting (XSS) in wp-object-cache

Description

WordPress' Object Cache that caches data from the database did not validate or encode the cache key. If an attacker managed to inject a malicious cache key that was then output in a third party plugin, it could lead to XSS.

Affects WordPress

Fixed in WordPress 5.4.1
Fixed in WordPress 5.3.3
Fixed in WordPress 5.3.3
Fixed in WordPress 5.3.3
Fixed in WordPress 5.2.6
Fixed in WordPress 5.2.6
Fixed in WordPress 5.2.6
Fixed in WordPress 5.2.6
Fixed in WordPress 5.2.6
Fixed in WordPress 5.2.6
Fixed in WordPress 5.1.5
Fixed in WordPress 5.1.5
Fixed in WordPress 5.1.5
Fixed in WordPress 5.1.5
Fixed in WordPress 5.1.5
Fixed in WordPress 5.0.9
Fixed in WordPress 5.0.9
Fixed in WordPress 5.0.9
Fixed in WordPress 5.0.9
Fixed in WordPress 5.0.9
Fixed in WordPress 5.0.9
Fixed in WordPress 5.0.9
Fixed in WordPress 5.0.9
Fixed in WordPress 4.9.14
Fixed in WordPress 4.9.14
Fixed in WordPress 4.9.14
Fixed in WordPress 4.9.14
Fixed in WordPress 4.9.14
Fixed in WordPress 4.9.14
Fixed in WordPress 4.9.14
Fixed in WordPress 4.9.14
Fixed in WordPress 4.9.14
Fixed in WordPress 4.9.14
Fixed in WordPress 4.9.14
Fixed in WordPress 4.9.14
Fixed in WordPress 4.9.14
Fixed in WordPress 4.9.14
Fixed in WordPress 4.8.13
Fixed in WordPress 4.8.13
Fixed in WordPress 4.8.13
Fixed in WordPress 4.8.13
Fixed in WordPress 4.8.13
Fixed in WordPress 4.8.13
Fixed in WordPress 4.8.13
Fixed in WordPress 4.8.13
Fixed in WordPress 4.8.13
Fixed in WordPress 4.8.13
Fixed in WordPress 4.8.13
Fixed in WordPress 4.8.13
Fixed in WordPress 4.8.13
Fixed in WordPress 4.7.17
Fixed in WordPress 4.7.17
Fixed in WordPress 4.7.17
Fixed in WordPress 4.7.17
Fixed in WordPress 4.7.17
Fixed in WordPress 4.7.17
Fixed in WordPress 4.7.17
Fixed in WordPress 4.7.17
Fixed in WordPress 4.7.17
Fixed in WordPress 4.7.17
Fixed in WordPress 4.7.17
Fixed in WordPress 4.7.17
Fixed in WordPress 4.7.17
Fixed in WordPress 4.7.17
Fixed in WordPress 4.7.17
Fixed in WordPress 4.7.17
Fixed in WordPress 4.7.17
Fixed in WordPress 4.6.18
Fixed in WordPress 4.6.18
Fixed in WordPress 4.6.18
Fixed in WordPress 4.6.18
Fixed in WordPress 4.6.18
Fixed in WordPress 4.6.18
Fixed in WordPress 4.6.18
Fixed in WordPress 4.6.18
Fixed in WordPress 4.6.18
Fixed in WordPress 4.6.18
Fixed in WordPress 4.6.18
Fixed in WordPress 4.6.18
Fixed in WordPress 4.6.18
Fixed in WordPress 4.6.18
Fixed in WordPress 4.6.18
Fixed in WordPress 4.6.18
Fixed in WordPress 4.6.18
Fixed in WordPress 4.6.18
Fixed in WordPress 4.5.21
Fixed in WordPress 4.5.21
Fixed in WordPress 4.5.21
Fixed in WordPress 4.5.21
Fixed in WordPress 4.5.21
Fixed in WordPress 4.5.21
Fixed in WordPress 4.5.21
Fixed in WordPress 4.5.21
Fixed in WordPress 4.5.21
Fixed in WordPress 4.5.21
Fixed in WordPress 4.5.21
Fixed in WordPress 4.5.21
Fixed in WordPress 4.5.21
Fixed in WordPress 4.5.21
Fixed in WordPress 4.5.21
Fixed in WordPress 4.5.21
Fixed in WordPress 4.5.21
Fixed in WordPress 4.5.21
Fixed in WordPress 4.5.21
Fixed in WordPress 4.5.21
Fixed in WordPress 4.5.21
Fixed in WordPress 4.4.22
Fixed in WordPress 4.4.22
Fixed in WordPress 4.4.22
Fixed in WordPress 4.4.22
Fixed in WordPress 4.4.22
Fixed in WordPress 4.4.22
Fixed in WordPress 4.4.22
Fixed in WordPress 4.4.22
Fixed in WordPress 4.4.22
Fixed in WordPress 4.4.22
Fixed in WordPress 4.4.22
Fixed in WordPress 4.4.22
Fixed in WordPress 4.4.22
Fixed in WordPress 4.4.22
Fixed in WordPress 4.4.22
Fixed in WordPress 4.4.22
Fixed in WordPress 4.4.22
Fixed in WordPress 4.4.22
Fixed in WordPress 4.4.22
Fixed in WordPress 4.4.22
Fixed in WordPress 4.4.22
Fixed in WordPress 4.4.22
Fixed in WordPress 4.3.23
Fixed in WordPress 4.3.23
Fixed in WordPress 4.3.23
Fixed in WordPress 4.3.23
Fixed in WordPress 4.3.23
Fixed in WordPress 4.3.23
Fixed in WordPress 4.3.23
Fixed in WordPress 4.3.23
Fixed in WordPress 4.3.23
Fixed in WordPress 4.3.23
Fixed in WordPress 4.3.23
Fixed in WordPress 4.3.23
Fixed in WordPress 4.3.23
Fixed in WordPress 4.3.23
Fixed in WordPress 4.3.23
Fixed in WordPress 4.3.23
Fixed in WordPress 4.3.23
Fixed in WordPress 4.3.23
Fixed in WordPress 4.3.23
Fixed in WordPress 4.3.23
Fixed in WordPress 4.3.23
Fixed in WordPress 4.3.23
Fixed in WordPress 4.3.23
Fixed in WordPress 4.2.27
Fixed in WordPress 4.2.27
Fixed in WordPress 4.2.27
Fixed in WordPress 4.2.27
Fixed in WordPress 4.2.27
Fixed in WordPress 4.2.27
Fixed in WordPress 4.2.27
Fixed in WordPress 4.2.27
Fixed in WordPress 4.2.27
Fixed in WordPress 4.2.27
Fixed in WordPress 4.2.27
Fixed in WordPress 4.2.27
Fixed in WordPress 4.2.27
Fixed in WordPress 4.2.27
Fixed in WordPress 4.2.27
Fixed in WordPress 4.2.27
Fixed in WordPress 4.2.27
Fixed in WordPress 4.2.27
Fixed in WordPress 4.2.27
Fixed in WordPress 4.2.27
Fixed in WordPress 4.2.27
Fixed in WordPress 4.2.27
Fixed in WordPress 4.2.27
Fixed in WordPress 4.2.27
Fixed in WordPress 4.2.27
Fixed in WordPress 4.2.27
Fixed in WordPress 4.2.27
Fixed in WordPress 4.1.30
Fixed in WordPress 4.1.30
Fixed in WordPress 4.1.30
Fixed in WordPress 4.1.30
Fixed in WordPress 4.1.30
Fixed in WordPress 4.1.30
Fixed in WordPress 4.1.30
Fixed in WordPress 4.1.30
Fixed in WordPress 4.1.30
Fixed in WordPress 4.1.30
Fixed in WordPress 4.1.30
Fixed in WordPress 4.1.30
Fixed in WordPress 4.1.30
Fixed in WordPress 4.1.30
Fixed in WordPress 4.1.30
Fixed in WordPress 4.1.30
Fixed in WordPress 4.1.30
Fixed in WordPress 4.1.30
Fixed in WordPress 4.1.30
Fixed in WordPress 4.1.30
Fixed in WordPress 4.1.30
Fixed in WordPress 4.1.30
Fixed in WordPress 4.1.30
Fixed in WordPress 4.1.30
Fixed in WordPress 4.1.30
Fixed in WordPress 4.1.30
Fixed in WordPress 4.1.30
Fixed in WordPress 4.1.30
Fixed in WordPress 4.1.30
Fixed in WordPress 4.1.30
Fixed in WordPress 4.0.30
Fixed in WordPress 4.0.30
Fixed in WordPress 4.0.30
Fixed in WordPress 4.0.30
Fixed in WordPress 4.0.30
Fixed in WordPress 4.0.30
Fixed in WordPress 4.0.30
Fixed in WordPress 4.0.30
Fixed in WordPress 4.0.30
Fixed in WordPress 4.0.30
Fixed in WordPress 4.0.30
Fixed in WordPress 4.0.30
Fixed in WordPress 4.0.30
Fixed in WordPress 4.0.30
Fixed in WordPress 4.0.30
Fixed in WordPress 4.0.30
Fixed in WordPress 4.0.30
Fixed in WordPress 4.0.30
Fixed in WordPress 4.0.30
Fixed in WordPress 4.0.30
Fixed in WordPress 4.0.30
Fixed in WordPress 4.0.30
Fixed in WordPress 4.0.30
Fixed in WordPress 4.0.30
Fixed in WordPress 4.0.30
Fixed in WordPress 4.0.30
Fixed in WordPress 4.0.30
Fixed in WordPress 4.0.30
Fixed in WordPress 4.0.30
Fixed in WordPress 4.0.30
Fixed in WordPress 3.9.31
Fixed in WordPress 3.9.31
Fixed in WordPress 3.9.31
Fixed in WordPress 3.9.31
Fixed in WordPress 3.9.31
Fixed in WordPress 3.9.31
Fixed in WordPress 3.9.31
Fixed in WordPress 3.9.31
Fixed in WordPress 3.9.31
Fixed in WordPress 3.9.31
Fixed in WordPress 3.9.31
Fixed in WordPress 3.9.31
Fixed in WordPress 3.9.31
Fixed in WordPress 3.9.31
Fixed in WordPress 3.9.31
Fixed in WordPress 3.9.31
Fixed in WordPress 3.9.31
Fixed in WordPress 3.9.31
Fixed in WordPress 3.9.31
Fixed in WordPress 3.9.31
Fixed in WordPress 3.9.31
Fixed in WordPress 3.9.31
Fixed in WordPress 3.9.31
Fixed in WordPress 3.9.31
Fixed in WordPress 3.9.31
Fixed in WordPress 3.9.31
Fixed in WordPress 3.9.31
Fixed in WordPress 3.9.31
Fixed in WordPress 3.9.31
Fixed in WordPress 3.9.31
Fixed in WordPress 3.9.31
Fixed in WordPress 3.8.33
Fixed in WordPress 3.8.33
Fixed in WordPress 3.8.33
Fixed in WordPress 3.8.33
Fixed in WordPress 3.8.33
Fixed in WordPress 3.8.33
Fixed in WordPress 3.8.33
Fixed in WordPress 3.8.33
Fixed in WordPress 3.8.33
Fixed in WordPress 3.8.33
Fixed in WordPress 3.8.33
Fixed in WordPress 3.8.33
Fixed in WordPress 3.8.33
Fixed in WordPress 3.8.33
Fixed in WordPress 3.8.33
Fixed in WordPress 3.8.33
Fixed in WordPress 3.8.33
Fixed in WordPress 3.8.33
Fixed in WordPress 3.8.33
Fixed in WordPress 3.8.33
Fixed in WordPress 3.8.33
Fixed in WordPress 3.8.33
Fixed in WordPress 3.8.33
Fixed in WordPress 3.8.33
Fixed in WordPress 3.8.33
Fixed in WordPress 3.8.33
Fixed in WordPress 3.8.33
Fixed in WordPress 3.8.33
Fixed in WordPress 3.8.33
Fixed in WordPress 3.8.33
Fixed in WordPress 3.8.33
Fixed in WordPress 3.8.33
Fixed in WordPress 3.8.33
Fixed in WordPress 3.7.33
Fixed in WordPress 3.7.33
Fixed in WordPress 3.7.33
Fixed in WordPress 3.7.33
Fixed in WordPress 3.7.33
Fixed in WordPress 3.7.33
Fixed in WordPress 3.7.33
Fixed in WordPress 3.7.33
Fixed in WordPress 3.7.33
Fixed in WordPress 3.7.33
Fixed in WordPress 3.7.33
Fixed in WordPress 3.7.33
Fixed in WordPress 3.7.33
Fixed in WordPress 3.7.33
Fixed in WordPress 3.7.33
Fixed in WordPress 3.7.33
Fixed in WordPress 3.7.33
Fixed in WordPress 3.7.33
Fixed in WordPress 3.7.33
Fixed in WordPress 3.7.33
Fixed in WordPress 3.7.33
Fixed in WordPress 3.7.33
Fixed in WordPress 3.7.33
Fixed in WordPress 3.7.33
Fixed in WordPress 3.7.33
Fixed in WordPress 3.7.33
Fixed in WordPress 3.7.33
Fixed in WordPress 3.7.33
Fixed in WordPress 3.7.33
Fixed in WordPress 3.7.33
Fixed in WordPress 3.7.33
Fixed in WordPress 3.7.33
Fixed in WordPress 3.7.33

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
Nick Daugherty from WordPress VIP / WordPress Security Team
Submitter
Ryan
Verified
No

Timeline

Publicly Published
2020-04-29 (about 5 years ago)
Added
2020-04-30 (about 5 years ago)
Last Updated
2020-05-02 (about 5 years ago)

Other