@wordpress/url is vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes
50
Medium Risk
Affected versions of this package are vulnerable to improperly controlled modification of dynamically determined object attributes via the block editor. This vulnerability allows an attacker to manipulate the object prototype by injecting malicious scripts. As a result, the attacker can potentially gain unauthorized access, modify sensitive data, or disrupt application behavior, compromising the security and integrity of the system.
You are affected if you are using a version that falls within the vulnerable range.
@wordpress/url is vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes in versions 2.0.0 - 3.7.0.
Upgrade the @wordpress/url library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant