Cross-site scripting in WordPress - #VU151461

 

Cross-site scripting in WordPress - #VU151461

Published: September 20, 2026


Vulnerability identifier: #VU151461
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: N/A
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary script.

The vulnerability exists due to improper neutralization of input during web page generation in the `wpautop()` function when processing a crafted comment. A remote attacker can post a comment containing a KSES-legal element with a newline in an attribute value to execute arbitrary script.

User interaction is required to view the rendered comment.


Affected software

WordPress

Remediation

Install security update from vendor's website.

WordPress - addressed in versions 4.7.36, 4.8.31, 4.9.32, 5.0.28, 5.1.25, 5.2.27, 5.3.24, 5.4.22, 5.5.21, 5.6.20, 5.7.18, 5.8.16, 5.9.17, 6.0.15, 6.1.13, 6.2.12, 6.3.11, 6.4.11, 6.5.11, 6.6.8, 6.7.8, 6.8.9, 6.9.8, 7.0.5, 7.1.1

External References

Related Security Bulletins