WordPress Vulnerabilities
WordPress < 5.4.1 - Cross-Site Scripting (XSS) in wp-object-cache
Description
WordPress' Object Cache that caches data from the database did not validate or encode the cache key. If an attacker managed to inject a malicious cache key that was then output in a third party plugin, it could lead to XSS.
Affects WordPress
References
CVE
Classification
Type
XSS
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Nick Daugherty from WordPress VIP / WordPress Security Team
Submitter
Ryan
Verified
No
WPVDB ID
Timeline
Publicly Published
2020-04-29 (about 5 years ago)
Added
2020-04-30 (about 5 years ago)
Last Updated
2020-05-02 (about 5 years ago)