Cross-site scripting vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to inject an arbitrary script
Published Dec 5, 2022
6.1
MEDIUMCVSS 3.1
EPSS 0.94%
Description
Cross-site scripting vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to inject an arbitrary script. The developer also provides new patched releases for all versions since 3.7.
Affected products
-
- Version versions prior to 6.0.3StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| WordPress.org | WordPress | n/a |
|
- < 3.7.40
- ≥ 3.8 · < 3.8.40
- ≥ 3.9 · < 3.9.39
- ≥ 4.0 · < 4.0.37
- ≥ 4.1 · < 4.1.37
- ≥ 4.2 · < 4.2.34
- ≥ 4.3 · < 4.3.30
- ≥ 4.4 · < 4.4.29
- ≥ 4.5 · < 4.5.28
- ≥ 4.6 · < 4.6.25
- ≥ 4.7 · < 4.7.25
- ≥ 4.8 · < 4.8.21
- ≥ 4.9 · < 4.9.22
- ≥ 5.0 · < 5.0.18
- ≥ 5.1 · < 5.1.15
- ≥ 5.2 · < 5.2.17
- ≥ 5.3 · < 5.3.14
- ≥ 5.4 · < 5.4.12
- ≥ 5.5 · < 5.5.11
- ≥ 5.6 · < 5.6.10
- ≥ 5.7 · < 5.7.8
- ≥ 5.8 · < 5.8.6
- ≥ 5.9 · < 5.9.5
- ≥ 6.0 · < 6.0.3
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Apr 24, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (14 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.94% (0.00942) | 59.59th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.73% (0.00729) | 49.24th | v5 (v2026.06.15) |
| Dec 27, 2025 | 1.63% (0.01625) | 81.46th | v4 (v2025.03.14) |
| Mar 17, 2025 | 0.53% (0.00527) | 65.15th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.19% (0.00194) | 58.30th | v3 (v2023.03.01) |
| Jun 27, 2024 | 0.19% (0.00194) | 57.18th | v3 (v2023.03.01) |
| May 17, 2024 | 0.18% (0.00177) | 54.65th | v3 (v2023.03.01) |
| Jan 6, 2024 | 0.16% (0.00160) | 52.55th | v3 (v2023.03.01) |
| Dec 11, 2023 | 0.15% (0.00149) | 50.73th | v3 (v2023.03.01) |
| Nov 4, 2023 | 0.08% (0.00083) | 34.78th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.08% (0.00077) | 31.15th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.14% (0.01136) | 59.45th | v2 (v2022.01.01) |
| Dec 7, 2022 | 1.14% (0.01136) | 58.52th | v2 (v2022.01.01) |
| Dec 6, 2022 | 1.06% (0.01061) | 51.77th | v2 (v2022.01.01) |
References (3)
- https://jvn.jp/en/jp/JVN09409909/index.html Third Party Advisory
- https://wordpress.org/download/ Product
- https://wordpress.org/news/2022/10/wordpress-6-0-3-security-release/ PatchRelease NotesVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://jvn.jp/en/jp/JVN09409909/index.html | Third Party Advisory | |
| https://wordpress.org/download/ | Product | |
| https://wordpress.org/news/2022/10/wordpress-6-0-3-security-release/ | PatchRelease NotesVendor Advisory |
Change history (0)
No recorded changes yet.