CVE-2015-5622Cross-site Scripting in Wordpress

Severity
3.5LOWNVD
EPSS
1.0%
top 23.37%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 3
Latest updateMay 17

Description

Cross-site scripting (XSS) vulnerability in WordPress before 4.2.3 allows remote authenticated users to inject arbitrary web script or HTML by leveraging the Author or Contributor role to place a crafted shortcode inside an HTML element, related to wp-includes/kses.php and wp-includes/shortcodes.php.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 6.8 | Impact: 2.9

Affected Packages3 packages

debiandebian/wordpress< wordpress 4.2.3+dfsg-1 (bookworm)
Debianwordpress/wordpress< 4.2.3+dfsg-1+3

Also affects: Debian Linux 8.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-cg2j-v6g7-3q66: Cross-site scripting (XSS) vulnerability in WordPress before 42022-05-17
OSV
CVE-2015-5622: Cross-site scripting (XSS) vulnerability in WordPress before 42015-08-03

📋Vendor Advisories

1
Debian
CVE-2015-5622: wordpress - Cross-site scripting (XSS) vulnerability in WordPress before 4.2.3 allows remote...2015

💬Community

4
HackerOne
[bbPress] Stored XSS in any forum post.2016-09-01
Bugzilla
CVE-2015-5622 CVE-2015-5623 wordpress: cross-site scripting and permission issue fixed in [fedora-all]2015-07-24
Bugzilla
CVE-2015-5622 CVE-2015-5623 wordpress: cross-site scripting and permission issue fixed in wordpress 4.2.32015-07-24
Bugzilla
CVE-2015-5622 CVE-2015-5623 wordpress: cross-site scripting and permission issue fixed in [epel-all]2015-07-24
CVE-2015-5622 — Cross-site Scripting in Wordpress | cvebase