CVE-2020-4049Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in Wordpress

Severity
2.4LOWNVD
EPSS
5.9%
top 9.41%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 12
Latest updateJun 18

Description

In affected versions of WordPress, when uploading themes, the name of the theme folder can be crafted in a way that could lead to JavaScript execution in /wp-admin on the themes page. This does require an admin to upload the theme, and is low severity self-XSS. This has been patched in version 5.4.2, along with all the previously affected versions via a minor release (5.3.4, 5.2.7, 5.1.6, 5.0.10, 4.9.15, 4.8.14, 4.7.18, 4.6.19, 4.5.22, 4.4.23, 4.3.24, 4.2.28, 4.1.31, 4.0.31, 3.9.32, 3.8.34, 3.7.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:NExploitability: 0.9 | Impact: 1.4

Affected Packages4 packages

debiandebian/wordpress< wordpress 5.4.2+dfsg1-1 (bookworm)
NVDwordpress/wordpress3.73.7.34+17
Debianwordpress/wordpress< 5.4.2+dfsg1-1+3
CVEListV5wordpress/wordpress-develop18 versions+17

Also affects: Debian Linux 10.0, 8.0, 9.0, Fedora 31, 32

Patches

🔴Vulnerability Details

1
OSV
CVE-2020-4049: In affected versions of WordPress, when uploading themes, the name of the theme folder can be crafted in a way that could lead to JavaScript execution2020-06-12

📋Vendor Advisories

1
Debian
CVE-2020-4049: wordpress - In affected versions of WordPress, when uploading themes, the name of the theme ...2020

💬Community

3
Bugzilla
CVE-2020-4049 wordpress: authenticated self-XSS via theme uploads [epel-all]2020-06-18
Bugzilla
CVE-2020-4049 wordpress: authenticated self-XSS via theme uploads [fedora-all]2020-06-18
Bugzilla
CVE-2020-4049 wordpress: authenticated self-XSS via theme uploads2020-06-18