Authenticated XSS via media attachment page in WordPress
Published Jun 12, 2020
6.8
MEDIUMCVSS 3.1
EPSS 3.27%
Description
In affected versions of WordPress, authenticated users with upload permissions (like authors) are able to inject JavaScript into some media file attachment pages in a certain way. This can lead to script execution in the context of a higher privileged user when the file is viewed by them. This has been patched in version 5.4.2, along with all the previously affected versions via a minor release (5.3.4, 5.2.7, 5.1.6, 5.0.10, 4.9.15, 4.8.14, 4.7.18, 4.6.19, 4.5.22, 4.4.23, 4.3.24, 4.2.28, 4.1.31, 4.0.31, 3.9.32, 3.8.34, 3.7.34).
Affected products
-
- Version >= 3.7.0, < 3.7.34StatusaffectedConstraints-
- Version >= 3.8.0, < 3.8.34StatusaffectedConstraints-
- Version >= 3.9.0, < 3.9.32StatusaffectedConstraints-
- Version >= 4.0.0, < 4.0.31StatusaffectedConstraints-
- Version >= 4.1.0, < 4.1.31StatusaffectedConstraints-
- Version >= 4.2.0, < 4.2.28StatusaffectedConstraints-
- Version >= 4.3.0, < 4.3.24StatusaffectedConstraints-
- Version >= 4.4.0, < 4.4.23StatusaffectedConstraints-
- Version >= 4.5.0, < 4.5.22StatusaffectedConstraints-
- Version >= 4.6.0, < 4.6.19StatusaffectedConstraints-
- Version >= 4.7.0, < 4.7.18StatusaffectedConstraints-
- Version >= 4.8.0, < 4.8.14StatusaffectedConstraints-
- Version >= 4.9.0, < 4.9.15StatusaffectedConstraints-
- Version >= 5.0.0, < 5.0.10StatusaffectedConstraints-
- Version >= 5.1.0, < 5.1.6StatusaffectedConstraints-
- Version >= 5.2.0, < 5.2.7StatusaffectedConstraints-
- Version >= 5.3.0, < 5.3.4StatusaffectedConstraints-
- Version >= 5.4.0, < 5.4.2StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| WordPress | Wordpress-Develop | n/a |
|
Configuration 1
- ≥ 3.7 · < 3.7.34
- ≥ 3.8 · < 3.8.34
- ≥ 3.9 · < 3.9.32
- ≥ 4.0 · < 4.0.31
- ≥ 4.1 · < 4.1.31
- ≥ 4.2 · < 4.2.28
- ≥ 4.3 · < 4.3.24
- ≥ 4.4 · < 4.4.23
- ≥ 4.5 · < 4.5.22
- ≥ 4.6 · < 4.6.19
- ≥ 4.7 · < 4.7.18
- ≥ 4.8 · < 4.8.14
- ≥ 4.9 · < 4.9.15
- ≥ 5.0 · < 5.0.10
- ≥ 5.1 · < 5.1.6
- ≥ 5.2 · < 5.2.7
- ≥ 5.3.0 · < 5.3.4
- ≥ 5.4 · < 5.4.2
Configuration 2
- 32
- 33
Configuration 3
- 8.0
- 9.0
- 10.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (8)
- https://github.com/WordPress/wordpress-develop/commit/0977c0d6b241479ecedfe19e96be69f727c3f81f x_refsource_MISCPatch
- https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-8q2w-5m27-wm27 x_refsource_CONFIRMThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/07/msg00000.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/09/msg00011.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/773N2ZV7QEMBGKH6FBKI6Q5S3YJMW357/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ODNHXVJS25YVWYQHOCICXTLIN5UYJFDN/ vendor-advisoryx_refsource_FEDORA
- https://wordpress.org/news/2020/06/wordpress-5-4-2-security-and-maintenance-release/ x_refsource_MISCRelease NotesVendor Advisory
- https://www.debian.org/security/2020/dsa-4709 vendor-advisoryx_refsource_DEBIANMailing ListThird Party Advisory
Change history (0)
No recorded changes yet.