Cross-site scripting in WordPress - #VU151464

 

Cross-site scripting in WordPress - #VU151464

Published: September 20, 2026


Vulnerability identifier: #VU151464
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: N/A
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary script code in a victim's browser.

The vulnerability exists due to improper neutralization of input during web page generation in custom-header preview handling when rendering stored custom-header information. A remote privileged user can store crafted custom-header information to execute arbitrary script code in a victim's browser.

Only themes that support custom headers and do not register an admin-preview-callback are affected.


Affected software

WordPress

Remediation

Install security update from vendor's website.

WordPress - addressed in versions 4.7.36, 4.8.31, 4.9.32, 5.0.28, 5.1.25, 5.2.27, 5.3.24, 5.4.22, 5.5.21, 5.6.20, 5.7.18, 5.8.16, 5.9.17, 6.0.15, 6.1.13, 6.2.12, 6.3.11, 6.4.11, 6.5.11, 6.6.8, 6.7.8, 6.8.9, 6.9.8, 7.0.5, 7.1.1

External References

Related Security Bulletins