Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:25676
HistoryJun 15, 2020 - 3:41 a.m.

Cross-site Scripting (XSS)

2020-06-1503:41:45
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12

EPSS

0.004

Percentile

73.8%

wordpress is vulnerable to cross-site scripting (XSS). The vulnerability exists as it was possible to use the embed block to inject unfiltered HTML through $post->post_content which would be executed in editor/wp-admin.