In WordPress before 5.3.1, authenticated users with lower privileges (like contributors) can inject JavaScript code in the block editor, which is executed within the dashboard. It can lead to an admin opening the affected post in the editor leading to XSS.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2019-12-26T17:00:17
Updated: 2024-08-05T01:24:48.284Z
Reserved: 2019-09-24T00:00:00
Link: CVE-2019-16781
Vulnrichment
No data.
NVD
Status : Modified
Published: 2019-12-26T17:15:13.613
Modified: 2024-11-21T04:31:10.783
Link: CVE-2019-16781
Redhat
No data.