CVE-2021-39201: Authenticated cross-site scripting (XSS) in WordPress editor
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. ### Impact The issue allows an authenticated but low-privileged user (like contributor/author) to execute XSS in the editor. This bypasses the restrictions imposed on users who do not have the permission to post unfilteredhtml. ### Patches This has been patched in WordPress 5.8, and will be pushed to older versions via minor releases (automatic updates). It's strongly recommended that you keep auto-updates enabled to receive the fix. ### References https://wordpress.org/news/category/releases/ https://hackerone.com/reports/1142140 ### For more information If you have any questions or comments about this advisory: Open an issue in HackerOne
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/wordpressto a version that resolves this vulnerability.Fixed in 5.0.15+dfsg1-0+deb10u1Fixed in 5.0.19+dfsg1-0+deb10u1Fixed in 5.7.8+dfsg1-0+deb11u2Fixed in 6.1.1+dfsg1-1Fixed in 6.3.1+dfsg1-1 - Upgrade
Upgrade
debian/wordpressto a version that resolves this vulnerability.Fixed in 5.8.1+dfsg1-1Fixed in 5.0.14+dfsg1-0+deb10u1Fixed in 5.7.3+dfsg1-0+deb11u1 - Upgrade
Upgrade
WordPressto a version that resolves this vulnerability.Fixed in 5.8 - Configuration
Keep auto-updates enabled to receive the XSS fix pushed to older versions via minor releases.
WordPress auto-updates enabled = enabled
Event History
Frequently Asked Questions
What is CVE-2021-39201?
CVE-2021-39201 is a vulnerability in WordPress that allows an authenticated but low-privileged user to execute XSS in the editor.
What is the impact of CVE-2021-39201?
The impact of CVE-2021-39201 is that it bypasses the restrictions imposed on users and allows for the execution of XSS in the editor.
Which versions of WordPress are affected by CVE-2021-39201?
WordPress versions 5.0 to 5.8 are affected by CVE-2021-39201.
How can I fix CVE-2021-39201 in Debian Linux?
You can fix CVE-2021-39201 in Debian Linux by updating to version 10.0 or 11.0.
Where can I find more information about CVE-2021-39201?
You can find more information about CVE-2021-39201 in the following references: [link1], [link2], [link3].