First published: Fri Jun 12 2020(Updated: )
In affected versions of WordPress, authenticated users with upload permissions (like authors) are able to inject JavaScript into some media file attachment pages in a certain way. This can lead to script execution in the context of a higher privileged user when the file is viewed by them. This has been patched in version 5.4.2, along with all the previously affected versions via a minor release (5.3.4, 5.2.7, 5.1.6, 5.0.10, 4.9.15, 4.8.14, 4.7.18, 4.6.19, 4.5.22, 4.4.23, 4.3.24, 4.2.28, 4.1.31, 4.0.31, 3.9.32, 3.8.34, 3.7.34).
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/wordpress | 5.0.15+dfsg1-0+deb10u1 5.0.19+dfsg1-0+deb10u1 5.7.8+dfsg1-0+deb11u2 6.1.1+dfsg1-1 6.3.1+dfsg1-1 | |
WordPress WordPress | >=3.7<3.7.34 | |
WordPress WordPress | >=3.8<3.8.34 | |
WordPress WordPress | >=3.9<3.9.32 | |
WordPress WordPress | >=4.0<4.0.31 | |
WordPress WordPress | >=4.1<4.1.31 | |
WordPress WordPress | >=4.2<4.2.28 | |
WordPress WordPress | >=4.3<4.3.24 | |
WordPress WordPress | >=4.4<4.4.23 | |
WordPress WordPress | >=4.5<4.5.22 | |
WordPress WordPress | >=4.6<4.6.19 | |
WordPress WordPress | >=4.7<4.7.18 | |
WordPress WordPress | >=4.8<4.8.14 | |
WordPress WordPress | >=4.9<4.9.15 | |
WordPress WordPress | >=5.0<5.0.10 | |
WordPress WordPress | >=5.1<5.1.6 | |
WordPress WordPress | >=5.2<5.2.7 | |
WordPress WordPress | >=5.3.0<5.3.4 | |
WordPress WordPress | >=5.4<5.4.2 | |
Fedoraproject Fedora | =32 | |
Fedoraproject Fedora | =33 | |
Debian Debian Linux | =8.0 | |
Debian Debian Linux | =9.0 | |
Debian Debian Linux | =10.0 |
https://github.com/WordPress/wordpress-develop/commit/0977c0d6b241479ecedfe19e96be69f727c3f81f
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability CVE-2020-4047 allows authenticated users with upload permissions to inject JavaScript into media file attachment pages, leading to script execution in the context of a higher privileged user.
WordPress versions 3.7 to 5.0.15, 5.0.19 to 5.7.8, 6.1.1 to 6.3.1, and some Debian and Fedoraproject versions are affected by CVE-2020-4047.
The severity of the vulnerability CVE-2020-4047 is medium with a CVSS score of 6.8.
To fix the vulnerability CVE-2020-4047, update your WordPress installation to a version that includes the security patch.
You can find more information about the vulnerability CVE-2020-4047 on the WordPress Core Trac and GitHub security advisories.