CVE-2015-5622 — Cross-site Scripting in Wordpress
Severity
3.5LOWNVD
EPSS
1.0%
top 23.37%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 3
Latest updateMay 17
Description
Cross-site scripting (XSS) vulnerability in WordPress before 4.2.3 allows remote authenticated users to inject arbitrary web script or HTML by leveraging the Author or Contributor role to place a crafted shortcode inside an HTML element, related to wp-includes/kses.php and wp-includes/shortcodes.php.
CVSS vector
AV:N/AC:M/C:N/I:P/A:NExploitability: 6.8 | Impact: 2.9
Affected Packages3 packages
Also affects: Debian Linux 8.0
Patches
🔴Vulnerability Details
2📋Vendor Advisories
1Debian▶
CVE-2015-5622: wordpress - Cross-site scripting (XSS) vulnerability in WordPress before 4.2.3 allows remote...↗2015
💬Community
4Bugzilla▶
CVE-2015-5622 CVE-2015-5623 wordpress: cross-site scripting and permission issue fixed in [fedora-all]↗2015-07-24
Bugzilla▶
CVE-2015-5622 CVE-2015-5623 wordpress: cross-site scripting and permission issue fixed in wordpress 4.2.3↗2015-07-24
Bugzilla▶
CVE-2015-5622 CVE-2015-5623 wordpress: cross-site scripting and permission issue fixed in [epel-all]↗2015-07-24