Vulnerability identifier: #VU151461
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: N/A
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary script.
The vulnerability exists due to improper neutralization of input during web page generation in the `wpautop()` function when processing a crafted comment. A remote attacker can post a comment containing a KSES-legal element with a newline in an attribute value to execute arbitrary script.
User interaction is required to view the rendered comment.
Affected software
WordPress
Remediation
Install security update from vendor's website.
WordPress - addressed in versions 4.7.36, 4.8.31, 4.9.32, 5.0.28, 5.1.25, 5.2.27, 5.3.24, 5.4.22, 5.5.21, 5.6.20, 5.7.18, 5.8.16, 5.9.17, 6.0.15, 6.1.13, 6.2.12, 6.3.11, 6.4.11, 6.5.11, 6.6.8, 6.7.8, 6.8.9, 6.9.8, 7.0.5, 7.1.1
External References
Related Security Bulletins