johnpbloch/wordpress-core is vulnerable to Cross-Site Scripting (XSS)
71
High Risk
WordPress core contains eleven independent security flaws across theme installation and preview, custom header images, private parent-post metadata, the HTML API, multisite plugin activation, post updates, REST template handling, comment reparenting, XML-RPC custom CSS changesets, draft and pending post slugs, and paragraph formatting. Depending on the attack path and the caller's privileges, these flaws allow automatic theme installation from a crafted URL, stored cross-site scripting, sensitive information disclosure, path traversal, arbitrary post overwrite, and bypasses of plugin, comment, and custom CSS authorization checks. The unauthenticated wpautop() flaw can store attacker-controlled script through comment paragraph formatting, subject to comment approval. The fix hardens input handling and enforces the missing capability, ownership, and authorization checks across all eleven affected components.
You are affected if you are using a version that falls within the vulnerable range.
johnpbloch/wordpress-core is vulnerable to Cross-Site Scripting (XSS) in versions 7.1.0 - 7.1.0, 7.0.0 - 7.0.4, 6.9.0 - 6.9.7, 6.8.0 - 6.8.8, 6.7.0 - 6.7.7, 6.6.0 - 6.6.7, 6.5.0 - 6.5.10, 6.4.0 - 6.4.10, 6.3.0 - 6.3.10, 6.2.0 - 6.2.11, 6.1.0 - 6.1.12, 6.0.0 - 6.0.14, 5.9.0 - 5.9.16, 5.8.0 - 5.8.15, 5.7.0 - 5.7.17, 5.6.0 - 5.6.19, 5.5.0 - 5.5.20, 5.4.0 - 5.4.21, 5.3.0 - 5.3.23, 5.2.0 - 5.2.26, 5.1.0 - 5.1.24, 5.0.0 - 5.0.27, 4.9.0 - 4.9.31, 4.8.0 - 4.8.30 and 4.7.0 - 4.7.35.
Upgrade the johnpbloch/wordpress-core library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.