PT-2019-5215 · WordPress · Wordpress

Simon Scannell

·

Publicado

2019-09-11

·

Atualizado

2023-01-19

·

CVE-2019-16781

CVSS v3.1

5.8

Média

VetorAV:N/AC:H/PR:L/UI:R/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions WordPress versions prior to 5.3.1
Description The issue is related to a Cross-Site Scripting (XSS) error in the block editor of the WordPress content management system. This error can be exploited by authenticated users with lower privileges, such as contributors, who can inject JavaScript code in the block editor. The injected code is executed within the dashboard, which can lead to an admin opening the affected post in the editor, resulting in an XSS attack. This can allow a remote attacker to compromise the integrity of the data.
Recommendations For versions prior to 5.3.1, update to version 5.3.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the block editor for lower-privileged users until a patch is applied.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2020-01944
CVE-2019-16781
DSA-4599-1
DSA-4677-1
GHSA-PG4X-64RH-3C9V

Produtos afetados

Wordpress