cbcvebase.
CVE-2019-16781
published 2019-12-26

CVE-2019-16781: In WordPress before 5.3.1, authenticated users with lower privileges (like contributors) can inject JavaScript code in the block editor, which is executed…

PriorityP425medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
1.40%
69.3th percentile
In WordPress before 5.3.1, authenticated users with lower privileges (like contributors) can inject JavaScript code in the block editor, which is executed within the dashboard. It can lead to an admin opening the affected post in the editor leading to XSS.

Affected

8 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianwordpress< wordpress 5.3.2+dfsg1-1 (bookworm)wordpress 5.3.2+dfsg1-1 (bookworm)
wordpresswordpress< 5.3.15.3.1
wordpresswordpress>= 0 < 5.3.2+dfsg1-15.3.2+dfsg1-1
wordpresswordpress>= 0 < 5.3.2+dfsg1-15.3.2+dfsg1-1
wordpresswordpress>= 0 < 5.3.2+dfsg1-15.3.2+dfsg1-1
wordpresswordpress>= 0 < 5.3.2+dfsg1-15.3.2+dfsg1-1

CVSS provenance

nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
osv5.4MEDIUM
vendor_debian5.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.