CVE-2021-39202: WordPress 5.8 beta: Stored Cross-Site Scripting (XSS) vulnerability in widget
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions the widgets editor introduced in WordPress 5.8 beta 1 has improper handling of HTML input in the Custom HTML feature. This leads to stored XSS in the custom HTML widget. This has been patched in WordPress 5.8. It was only present during the testing/beta phase of WordPress 5.8.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpressto a version that resolves this vulnerability.Fixed in 5.8
Event History
Frequently Asked Questions
What is the severity of CVE-2021-39202?
The severity of CVE-2021-39202 is high with a CVSS score of 5.4.
How does CVE-2021-39202 affect WordPress?
CVE-2021-39202 affects WordPress versions 5.8 beta 1 and 5.8 beta 2.
What is the vulnerability type of CVE-2021-39202?
CVE-2021-39202 is a stored cross-site scripting (XSS) vulnerability.
How can I fix CVE-2021-39202 in WordPress?
To fix CVE-2021-39202 in WordPress, update to a version that includes the security patch.
Where can I find more information about CVE-2021-39202?
More information about CVE-2021-39202 can be found in the GitHub advisory and HackerOne report.