PT-2024-37528 · WordPress+1 · Wordpress+1
Aaron Jorbin
+3
·
Published
2024-06-25
·
Updated
2025-12-10
·
CVE-2024-6307
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
WordPress Core versions prior to 6.5.5
Description:
The issue is related to Stored Cross-Site Scripting via the HTML API due to insufficient input sanitization and output escaping on URLs. This allows authenticated attackers with contributor-level access and above to inject arbitrary web scripts in pages, which will execute when a user accesses an injected page.
Recommendations:
For versions prior to 6.5.5, update to version 6.5.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the HTML API for users with contributor-level access and above until the update is applied. Additionally, ensure proper input validation and output escaping on URLs to prevent similar issues in the future.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debian
Wordpress