Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:27742
HistoryNov 03, 2020 - 7:36 a.m.

Cross-site Scripting (XSS)

2020-11-0307:36:19
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
21
wordpress
xss
vulnerability
admin-header.php
addloadevent
malicious script
global variables
user visit
software

EPSS

0.035

Percentile

91.7%

wordpress is vulnerable to cross-site scripting (XSS). The vulnerability exists in the addLoadEvent function in admin-header.php where an attacker is able to inject malicious script via global variables and get it executed when a user visits the page.