johnpbloch/wordpress-core is vulnerable to Cross-Site Scripting (XSS)
89
High Risk
The WordPress login screen reflects attacker-controlled input without adequate escaping, allowing pre-authentication reflected cross-site scripting. Through a crafted third-party page and successful social engineering, that XSS can be escalated to PHP code execution under conditions outside the attacker's control. The fix escapes the reflected login-screen values so the payload cannot run in the victim's browser.
You are affected if you are using a version that falls within the vulnerable range and users can be induced to visit an attacker-controlled page that targets the WordPress login screen.
johnpbloch/wordpress-core is vulnerable to Cross-Site Scripting (XSS) in versions 7.0.0 - 7.0.2, 6.9.0 - 6.9.5, 6.8.0 - 6.8.6, 6.7.0 - 6.7.5, 6.6.0 - 6.6.5, 6.5.0 - 6.5.8, 6.4.0 - 6.4.8, 6.3.0 - 6.3.8, 6.2.0 - 6.2.9, 6.1.0 - 6.1.10, 6.0.0 - 6.0.12, 5.9.0 - 5.9.13, 5.8.0 - 5.8.13, 5.7.0 - 5.7.15, 5.6.0 - 5.6.17, 5.5.0 - 5.5.18, 5.4.0 - 5.4.19, 5.3.0 - 5.3.21, 5.2.0 - 5.2.24, 5.1.0 - 5.1.22, 5.0.0 - 5.0.25, 4.9.0 - 4.9.29, 4.8.0 - 4.8.28 and 3.7.38 - 4.7.33.
Upgrade the johnpbloch/wordpress-core library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant