PT-2021-4511 · WordPress · Wordpress

Ehti

·

Published

2021-09-09

·

Updated

2024-03-06

·

CVE-2021-39201

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions WordPress versions prior to 5.8
Description The issue allows an authenticated but low-privileged user, such as a contributor or author, to execute cross-site scripting (XSS) in the editor, bypassing restrictions imposed on users who do not have the permission to post unfiltered html.
Recommendations For versions prior to 5.8, update to WordPress 5.8 or enable auto-updates to receive the fix via minor releases. As a temporary workaround, consider restricting the use of the editor for low-privileged users until a patch is available. Keep auto-updates enabled to receive the fix.

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2021-05149
BIT-WORDPRESS-2021-39201
BIT-WORDPRESS-MULTISITE-2021-39201
CVE-2021-39201
DSA-4985-1
GHSA-WH69-25HR-H94V

Affected Products

Wordpress