CVE-2021-39202
WordPress 5.8 beta: Stored Cross-Site Scripting (XSS) vulnerability in widget
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions the widgets editor introduced in WordPress 5.8 beta 1 has improper handling of HTML input in the Custom HTML feature. This leads to stored XSS in the custom HTML widget. This has been patched in WordPress 5.8. It was only present during the testing/beta phase of WordPress 5.8.
WordPress es un sistema de administración de contenidos gratuito y de código abierto escrito en PHP y emparejado con una base de datos MySQL o MariaDB. En versiones afectadas, el editor de widgets introducido en la versión 5.8 beta 1 de WordPress, presenta un manejo inapropiado de la entrada HTML en la funcionalidad Custom HTML. Esto conlleva a una vulnerabilidad de tipo XSS almacenado en el widget de HTML personalizado. Esto ha sido parcheado en WordPress versión 5.8. Sólo estuvo presente durante la fase de pruebas/beta de WordPress versión 5.8
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-08-16 CVE Reserved
- 2021-09-09 CVE Published
- 2023-04-02 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-fr6h-3855-j297 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 5.8 Search vendor "Wordpress" for product "Wordpress" and version "5.8" | beta1 |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 5.8 Search vendor "Wordpress" for product "Wordpress" and version "5.8" | beta2 |
Affected
|