Impact
The vulnerability is a stored cross‑site scripting flaw that enables an authenticated user with Author or higher role to insert malicious scripts into site content. Inadequate neutralization of input can cause scripts to run in any visitor's browser when the compromised content is viewed, potentially allowing defacement or other malicious actions.
Affected Systems
WordPress core versions from 6.8.2 down to 4.7.31 are affected. The flaw applies to all releases in the ranges listed by the WordPress security team, including 6.8, 6.7, 6.6, 6.5, 6.4, 6.3, 6.2, 6.1, 6.0, 5.9, 5.8, 5.7, 5.6, 5.5, 5.4, 5.3, 5.2, 5.1, 5.0, 4.9, 4.8, and 4.7.
Risk and Exploitability
The CVSS score of 5.9 classifies the flaw as moderate severity, while the EPSS score of less than 1% signals a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Attackers must first authenticate to WordPress with author or higher privileges and then create or edit content to embed the malicious script. Once the content is accessed by other visitors, the injected code executes in their browsers.
OpenCVE Enrichment
Debian DLA
Debian DSA
EUVD