Cross-site scripting in WordPress - #VU151464
Published: September 20, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary script code in a victim's browser.
The vulnerability exists due to improper neutralization of input during web page generation in custom-header preview handling when rendering stored custom-header information. A remote privileged user can store crafted custom-header information to execute arbitrary script code in a victim's browser.
Only themes that support custom headers and do not register an admin-preview-callback are affected.