WordPress Core < 5.2.4 - Authenticated Stored Cross-Site Scripting via Customizer
2019-10-14 00:00
Evan RicafortStrategic Overview
StatusPatched in 3.7.31
Affected CoreWordPress 5.2
Affected Version
3.7 – 5.2.3 · 17 branchesCVSS5.5Medium
CVE
CVE-2019-17674Vulnerability Overview
WordPress before 5.2.4 is vulnerable to stored XSS (cross-site scripting) via the Customizer.
Technical Analysis
REMEDIATION: Update to one of the following versions, or a newer patched version: 3.7.31, 3.8.31, 3.9.29, 4.0.28, 4.1.28, 4.2.25, 4.3.21, 4.4.20, 4.5.19, 4.6.16, 4.7.15, 4.8.11, 4.9.12, 5.0.7, 5.1.3, 5.2.4 --- IDENTIFIER: CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')) The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C