Intel

AIKIDO-2026-180761

johnpbloch/wordpress-core is vulnerable to Cross-Site Scripting (XSS)

Cross-Site Scripting (XSS)CVE-2026-93485 Published 3 days ago

71

High Risk

This Affects:

PHPjohnpbloch/wordpress-core
4.7.0 - 4.7.35
Fixed in 4.7.36
4.8.0 - 4.8.30
Fixed in 4.8.31
4.9.0 - 4.9.31
Fixed in 4.9.32
5.0.0 - 5.0.27
Fixed in 5.0.28
5.1.0 - 5.1.24
Fixed in 5.1.25
5.2.0 - 5.2.26
Fixed in 5.2.27
5.3.0 - 5.3.23
Fixed in 5.3.24
5.4.0 - 5.4.21
Fixed in 5.4.22
5.5.0 - 5.5.20
Fixed in 5.5.21
5.6.0 - 5.6.19
Fixed in 5.6.20
5.7.0 - 5.7.17
Fixed in 5.7.18
5.8.0 - 5.8.15
Fixed in 5.8.16
5.9.0 - 5.9.16
Fixed in 5.9.17
6.0.0 - 6.0.14
Fixed in 6.0.15
6.1.0 - 6.1.12
Fixed in 6.1.13
6.2.0 - 6.2.11
Fixed in 6.2.12
6.3.0 - 6.3.10
Fixed in 6.3.11
6.4.0 - 6.4.10
Fixed in 6.4.11
6.5.0 - 6.5.10
Fixed in 6.5.11
6.6.0 - 6.6.7
Fixed in 6.6.8
6.7.0 - 6.7.7
Fixed in 6.7.8
6.8.0 - 6.8.8
Fixed in 6.8.9
6.9.0 - 6.9.7
Fixed in 6.9.8
7.0.0 - 7.0.4
Fixed in 7.0.5
7.1.0 - 7.1.0
Fixed in 7.1.1
Are you affected? Scan for Free

TL;DR

WordPress core contains eleven independent security flaws across theme installation and preview, custom header images, private parent-post metadata, the HTML API, multisite plugin activation, post updates, REST template handling, comment reparenting, XML-RPC custom CSS changesets, draft and pending post slugs, and paragraph formatting. Depending on the attack path and the caller's privileges, these flaws allow automatic theme installation from a crafted URL, stored cross-site scripting, sensitive information disclosure, path traversal, arbitrary post overwrite, and bypasses of plugin, comment, and custom CSS authorization checks. The unauthenticated wpautop() flaw can store attacker-controlled script through comment paragraph formatting, subject to comment approval. The fix hardens input handling and enforces the missing capability, ownership, and authorization checks across all eleven affected components.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

johnpbloch/wordpress-core is vulnerable to Cross-Site Scripting (XSS) in versions 7.1.0 - 7.1.0, 7.0.0 - 7.0.4, 6.9.0 - 6.9.7, 6.8.0 - 6.8.8, 6.7.0 - 6.7.7, 6.6.0 - 6.6.7, 6.5.0 - 6.5.10, 6.4.0 - 6.4.10, 6.3.0 - 6.3.10, 6.2.0 - 6.2.11, 6.1.0 - 6.1.12, 6.0.0 - 6.0.14, 5.9.0 - 5.9.16, 5.8.0 - 5.8.15, 5.7.0 - 5.7.17, 5.6.0 - 5.6.19, 5.5.0 - 5.5.20, 5.4.0 - 5.4.21, 5.3.0 - 5.3.23, 5.2.0 - 5.2.26, 5.1.0 - 5.1.24, 5.0.0 - 5.0.27, 4.9.0 - 4.9.31, 4.8.0 - 4.8.30 and 4.7.0 - 4.7.35.

How to fix this

Upgrade the johnpbloch/wordpress-core library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform