johnpbloch/wordpress-core is vulnerable to Acceptance of Extraneous Untrusted Data With Trusted Data
69
Medium Risk
Affected versions of this package are vulnerable to the acceptance of extraneous untrusted data alongside trusted data during the processing of shortcodes in user-generated content. This flaw allows an attacker to inject and manipulate content by submitting crafted comments or other forms of input. Exploiting this vulnerability can alter content display or functionality, potentially misleading users, disrupting application behavior, or introducing malicious elements.
You are affected if you are using a version that falls within the vulnerable range.
johnpbloch/wordpress-core is vulnerable to Acceptance of Extraneous Untrusted Data With Trusted Data in versions 5.9.0 - 5.9.6, 6.0.0 - 6.0.4, 6.1.0 - 6.1.2 and 6.2.0 - 6.2.1.
Upgrade the johnpbloch/wordpress-core library to a patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant