Impact
WordPress core improperly neutralizes user input, resulting in a DOM‑based cross‑site scripting vulnerability (CWE-79). An attacker can inject malicious script into a web page rendered by WordPress. When a victim visits that page, the script runs in the victim’s browser, enabling attackers to capture cookies, hijack sessions, deface content, or launch phishing attacks. The issue is pronounced for users within the site or anyone who views the affected content.
Affected Systems
The flaw affects the Automattic WordPress core across a wide range of releases, from 4.7 through the 7.1 line. Versions 7.1 and earlier, 7.0 through 7.0.4, 6.9 through 6.9.7, 6.8 through 6.8.8, 6.7 through 6.7.7, 6.6 through 6.6.7, 6.5 through 6.5.10, 6.4 through 6.4.10, 6.3 through 6.3.10, 6.2 through 6.2.11, 6.1 through 6.1.12, 6.0 through 6.0.14, 5.9 through 5.9.16, 5.8 through 5.8.15, 5.7 through 5.7.17, 5.6 through 5.6.19, 5.5 through 5.5.20, 5.4 through 5.4.21, 5.3 through 5.3.23, 5.2 through 5.2.26, 5.1 through 5.1.24, 5.0 through 5.0.27, 4.9 through 4.9.31, 4.8 through 4.8.30 and 4.7 through 4.7.35 are all impacted.
Risk and Exploitability
The CVSS score of 7.1 indicates a high‑severity flaw. EPSS is reported as < 1 %, meaning the overall likelihood of exploitation remains low at present. The vulnerability is not listed in the CISA KEV catalog. Attackers can execute it without authentication via web requests (e.g., by posting a crafted comment that bypasses the default moderation requirement). Successful exploitation results in client‑side code execution that can be leveraged for a range of attacks, including session hijacking and phishing.
OpenCVE Enrichment
Debian DSA