CVE-2019-20042
published 2019-12-27CVE-2019-20042: In wp-includes/formatting.php in WordPress 3.7 to 5.3.0, the function wp_targeted_link_rel() can be used in a particular way to result in a stored cross-site…
PriorityP429medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
2.76%
84.6th percentile
In wp-includes/formatting.php in WordPress 3.7 to 5.3.0, the function wp_targeted_link_rel() can be used in a particular way to result in a stored cross-site scripting (XSS) vulnerability. This has been patched in WordPress 5.3.1, along with all the previous WordPress versions from 3.7 to 5.3 via a minor release.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | wordpress | < wordpress 5.3.2+dfsg1-1 (bookworm) | wordpress 5.3.2+dfsg1-1 (bookworm) |
| wordpress | wordpress | >= 0 < 5.3.2+dfsg1-1 | 5.3.2+dfsg1-1 |
| wordpress | wordpress | >= 0 < 5.3.2+dfsg1-1 | 5.3.2+dfsg1-1 |
| wordpress | wordpress | >= 0 < 5.3.2+dfsg1-1 | 5.3.2+dfsg1-1 |
| wordpress | wordpress | >= 0 < 5.3.2+dfsg1-1 | 5.3.2+dfsg1-1 |
| wordpress | wordpress | >= 3.7 < 5.3.1 | 5.3.1 |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv6.1MEDIUM
vendor_debian6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xgvp-37rp-x96c: WordPress before 5
ghsa_unreviewed·2022-05-24
CVE-2019-20042 [MEDIUM] CWE-79 GHSA-xgvp-37rp-x96c: WordPress before 5
WordPress before 5.3.1 allowed an attacker to create a cross-site scripting attack (XSS) in well crafted links, because of an insufficient protection mechanism in wp_targeted_link_rel in wp-includes/formatting.php.
OSV
CVE-2019-20042: In wp-includes/formatting
osv·2019-12-27·CVSS 6.1
CVE-2019-20042 [MEDIUM] CVE-2019-20042: In wp-includes/formatting
In wp-includes/formatting.php in WordPress 3.7 to 5.3.0, the function wp_targeted_link_rel() can be used in a particular way to result in a stored cross-site scripting (XSS) vulnerability. This has been patched in WordPress 5.3.1, along with all the previous WordPress versions from 3.7 to 5.3 via a minor release.
Debian
CVE-2019-20042: wordpress - In wp-includes/formatting.php in WordPress 3.7 to 5.3.0, the function wp_targete...
vendor_debian·2019·CVSS 6.1
CVE-2019-20042 [MEDIUM] CVE-2019-20042: wordpress - In wp-includes/formatting.php in WordPress 3.7 to 5.3.0, the function wp_targete...
In wp-includes/formatting.php in WordPress 3.7 to 5.3.0, the function wp_targeted_link_rel() can be used in a particular way to result in a stored cross-site scripting (XSS) vulnerability. This has been patched in WordPress 5.3.1, along with all the previous WordPress versions from 3.7 to 5.3 via a minor release.
Scope: local
bookworm: resolved (fixed in 5.3.2+dfsg1-1)
bullseye: resolved (fixed in 5.3.2+dfsg1-1)
forky: resolved (fixed in 5.3.2+dfsg1-1)
sid: resolved (fixed in 5.3.2+dfsg1-1)
trixie: resolved (fixed in 5.3.2+dfsg1-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-20042 wordpress: XSS through wp_targeted_link_rel [epel-7]
bugzilla·2020-01-21·CVSS 6.1
CVE-2019-20042 [MEDIUM] CVE-2019-20042 wordpress: XSS through wp_targeted_link_rel [epel-7]
CVE-2019-20042 wordpress: XSS through wp_targeted_link_rel [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following template to for the 'fedpkg update'
Bugzilla
CVE-2019-20042 wordpress: XSS through wp_targeted_link_rel [epel-6]
bugzilla·2020-01-21·CVSS 6.1
CVE-2019-20042 [MEDIUM] CVE-2019-20042 wordpress: XSS through wp_targeted_link_rel [epel-6]
CVE-2019-20042 wordpress: XSS through wp_targeted_link_rel [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-6.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following template to for the 'fedpkg update'
Bugzilla
CVE-2019-20042 wordpress: XSS through wp_targeted_link_rel
bugzilla·2020-01-21·CVSS 6.1
CVE-2019-20042 [MEDIUM] CVE-2019-20042 wordpress: XSS through wp_targeted_link_rel
CVE-2019-20042 wordpress: XSS through wp_targeted_link_rel
In wp-includes/formatting.php in WordPress 3.7 to 5.3.0, the function wp_targeted_link_rel() can be used in a particular way to result in a stored cross-site scripting (XSS) vulnerability. This has been patched in WordPress 5.3.1, along with all the previous WordPress versions from 3.7 to 5.3 via a minor release.
References:
https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-xvg2-m2f4-83m7
https://hackerone.com/reports/509930
Upstream commit:
https://github.com/WordPress/wordpress-develop/commit/1f7f3f1f59567e2504f0fbebd51ccf004b3ccb1d
Discussion:
Created wordpress tracking bugs for this issue:
Affects: epel-6 [bug 1793616]
Affects: epel-7 [bug 1793617]
https://blog.ripstech.com/filter/vulnerabilities/https://core.trac.wordpress.org/changeset/46894/trunkhttps://github.com/WordPress/wordpress-develop/commit/1f7f3f1f59567e2504f0fbebd51ccf004b3ccb1dhttps://github.com/WordPress/wordpress-develop/security/advisories/GHSA-xvg2-m2f4-83m7https://hackerone.com/reports/509930https://seclists.org/bugtraq/2020/Jan/8https://wordpress.org/news/2019/12/wordpress-5-3-1-security-and-maintenance-release/https://wpvulndb.com/vulnerabilities/9975https://www.debian.org/security/2020/dsa-4599https://www.debian.org/security/2020/dsa-4677https://blog.ripstech.com/filter/vulnerabilities/https://core.trac.wordpress.org/changeset/46894/trunkhttps://github.com/WordPress/wordpress-develop/commit/1f7f3f1f59567e2504f0fbebd51ccf004b3ccb1dhttps://github.com/WordPress/wordpress-develop/security/advisories/GHSA-xvg2-m2f4-83m7https://hackerone.com/reports/509930https://seclists.org/bugtraq/2020/Jan/8https://wordpress.org/news/2019/12/wordpress-5-3-1-security-and-maintenance-release/https://wpvulndb.com/vulnerabilities/9975https://www.debian.org/security/2020/dsa-4599https://www.debian.org/security/2020/dsa-4677
2019-12-27
Published