Intel

AIKIDO-2025-10039

johnpbloch/wordpress-core is vulnerable to Acceptance of Extraneous Untrusted Data With Trusted Data

Acceptance of Extraneous Untrusted Data With Trusted Data Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Jan 24, 2025

69

Medium Risk

This Affects:

PHPjohnpbloch/wordpress-core
5.9.0 - 5.9.6
Fixed in 5.9.7
6.0.0 - 6.0.4
Fixed in 6.0.5
6.1.0 - 6.1.2
Fixed in 6.1.3
6.2.0 - 6.2.1
Fixed in 6.2.2
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to the acceptance of extraneous untrusted data alongside trusted data during the processing of shortcodes in user-generated content. This flaw allows an attacker to inject and manipulate content by submitting crafted comments or other forms of input. Exploiting this vulnerability can alter content display or functionality, potentially misleading users, disrupting application behavior, or introducing malicious elements.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

johnpbloch/wordpress-core is vulnerable to Acceptance of Extraneous Untrusted Data With Trusted Data in versions 5.9.0 - 5.9.6, 6.0.0 - 6.0.4, 6.1.0 - 6.1.2 and 6.2.0 - 6.2.1.

How to fix this

Upgrade the johnpbloch/wordpress-core library to a patch version.