Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:21504
HistorySep 12, 2019 - 10:28 p.m.

Cross-site Scripting (XSS)

2019-09-1222:28:49
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
16

EPSS

0.032

Percentile

91.4%

wordpress is vulnerable to cross-site scripting (XSS). The attack is due to not handling of the existing rel attribute in wp_rel_nofollow_calback(), allowing an attacker to inject arbitrary script during shortcode previews.