WordPress Core < 5.2.4 - Authenticated Stored Cross-Site Scripting via Customizer

2019-10-14 00:00
Evan Ricafort

Strategic Overview

Status
Patched in 3.7.31
Affected CoreWordPress 5.2
Affected Version3.7 – 5.2.3 · 17 branches
CVSS5.5Medium
CVECVE-2019-17674
View all WordPress 5.2 vulnerabilities

Vulnerability Overview

WordPress before 5.2.4 is vulnerable to stored XSS (cross-site scripting) via the Customizer.

Technical Analysis

REMEDIATION: Update to one of the following versions, or a newer patched version: 3.7.31, 3.8.31, 3.9.29, 4.0.28, 4.1.28, 4.2.25, 4.3.21, 4.4.20, 4.5.19, 4.6.16, 4.7.15, 4.8.11, 4.9.12, 5.0.7, 5.1.3, 5.2.4 --- IDENTIFIER: CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')) The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C