CVE-2022-43500
WordPress Core < 6.0.3 & Gutenberg < 14.3.1 - Authenticated Cross-Site Scripting in Various Blocks
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Cross-site scripting vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to inject an arbitrary script. The developer also provides new patched releases for all versions since 3.7.
Una vulnerabilidad de Cross-Site Scripting en versiones de WordPress anteriores a la 6.0.3 permite que un atacante remoto no autenticado inyecte un script arbitrario. El desarrollador tambiƩn proporciona nuevas versiones parcheadas para todas las versiones desde la 3.7.
WordPress Core in versions up to 6.0.3 and the Gutenberg plugin for WordPress in versions up to 14.3.1 are vulnerable to Stored Cross-Site Scripting due to insufficient output escaping on user supplied input. The RSS widget, Search Block, Featured Image Block, RSS Block, and Navigation Block are all affected components. This makes it possible for authenticated users with access to the block editor to inject malicious web scripts that may execute whenever accessing the page.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2022-10-18 CVE Published
- 2022-10-22 CVE Reserved
- 2025-03-30 EPSS Updated
- 2025-04-30 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://jvn.jp/en/jp/JVN09409909/index.html | Third Party Advisory | |
https://wordpress.org/download | Product |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://wordpress.org/news/2022/10/wordpress-6-0-3-security-release | 2023-02-03 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | < 3.7.40 Search vendor "Wordpress" for product "Wordpress" and version " < 3.7.40" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | >= 3.8 < 3.8.40 Search vendor "Wordpress" for product "Wordpress" and version " >= 3.8 < 3.8.40" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | >= 3.9 < 3.9.39 Search vendor "Wordpress" for product "Wordpress" and version " >= 3.9 < 3.9.39" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | >= 4.0 < 4.0.37 Search vendor "Wordpress" for product "Wordpress" and version " >= 4.0 < 4.0.37" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | >= 4.1 < 4.1.37 Search vendor "Wordpress" for product "Wordpress" and version " >= 4.1 < 4.1.37" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | >= 4.2 < 4.2.34 Search vendor "Wordpress" for product "Wordpress" and version " >= 4.2 < 4.2.34" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | >= 4.3 < 4.3.30 Search vendor "Wordpress" for product "Wordpress" and version " >= 4.3 < 4.3.30" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | >= 4.4 < 4.4.29 Search vendor "Wordpress" for product "Wordpress" and version " >= 4.4 < 4.4.29" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | >= 4.5 < 4.5.28 Search vendor "Wordpress" for product "Wordpress" and version " >= 4.5 < 4.5.28" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | >= 4.6 < 4.6.25 Search vendor "Wordpress" for product "Wordpress" and version " >= 4.6 < 4.6.25" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | >= 4.7 < 4.7.25 Search vendor "Wordpress" for product "Wordpress" and version " >= 4.7 < 4.7.25" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | >= 4.8 < 4.8.21 Search vendor "Wordpress" for product "Wordpress" and version " >= 4.8 < 4.8.21" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | >= 4.9 < 4.9.22 Search vendor "Wordpress" for product "Wordpress" and version " >= 4.9 < 4.9.22" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | >= 5.0 < 5.0.18 Search vendor "Wordpress" for product "Wordpress" and version " >= 5.0 < 5.0.18" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | >= 5.1 < 5.1.15 Search vendor "Wordpress" for product "Wordpress" and version " >= 5.1 < 5.1.15" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | >= 5.2 < 5.2.17 Search vendor "Wordpress" for product "Wordpress" and version " >= 5.2 < 5.2.17" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | >= 5.3 < 5.3.14 Search vendor "Wordpress" for product "Wordpress" and version " >= 5.3 < 5.3.14" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | >= 5.4 < 5.4.12 Search vendor "Wordpress" for product "Wordpress" and version " >= 5.4 < 5.4.12" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | >= 5.5 < 5.5.11 Search vendor "Wordpress" for product "Wordpress" and version " >= 5.5 < 5.5.11" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | >= 5.6 < 5.6.10 Search vendor "Wordpress" for product "Wordpress" and version " >= 5.6 < 5.6.10" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | >= 5.7 < 5.7.8 Search vendor "Wordpress" for product "Wordpress" and version " >= 5.7 < 5.7.8" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | >= 5.8 < 5.8.6 Search vendor "Wordpress" for product "Wordpress" and version " >= 5.8 < 5.8.6" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | >= 5.9 < 5.9.5 Search vendor "Wordpress" for product "Wordpress" and version " >= 5.9 < 5.9.5" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | >= 6.0 < 6.0.3 Search vendor "Wordpress" for product "Wordpress" and version " >= 6.0 < 6.0.3" | - |
Affected
|