CVE-2024-31111Cross-site Scripting in Wordpress

Severity
6.5MEDIUMNVD
EPSS
0.4%
top 37.24%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 25

Description

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Automattic WordPress allows Stored XSS.This issue affects WordPress: from 6.5 through 6.5.4, from 6.4 through 6.4.4, from 6.3 through 6.3.4, from 6.2 through 6.2.5, from 6.1 through 6.1.6, from 6.0 through 6.0.8, from 5.9 through 5.9.9.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:LExploitability: 2.3 | Impact: 3.7

Affected Packages3 packages

CVEListV5automattic/wordpress6.56.5.4+6
debiandebian/wordpress< wordpress 6.1.9+dfsg1-0+deb12u1 (bookworm)
Debianwordpress/wordpress< 5.7.14+dfsg1-0+deb11u1+3

🔴Vulnerability Details

2
OSV
CVE-2024-31111: Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Automattic WordPress allows Stored XSS2024-06-25
GHSA
GHSA-99h6-m3cc-x9j3: Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Automattic WordPress allows Stored XSS2024-06-25

📋Vendor Advisories

1
Debian
CVE-2024-31111: wordpress - Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site ...2024