| VID |
210282 |
| Severity |
30 |
| Port |
80, ... |
| Protocol |
TCP |
| Class |
CGI |
| Detailed Description |
WordPress versions 6.0 to 6.5.5 are affected by one or more vulnerabilities:
- A cross-site scripting (XSS) vulnerability affecting the HTML API. - A cross-site scripting (XSS) vulnerability affecting the Template Part block. - A path traversal issue affecting sites hosted on Windows.
* References: https://wordpress.org/download/releases/ https://wordpress.org/news/2024/06/wordpress-6-5-5/ https://wordpress.org/documentation/wordpress-version/version-6-5-5/
* Platforms Affected: WordPress prior equal to 6.5.5 Any operating system Any version |
| Recommendation |
Upgrade to the version (6.5.5 or later) fixed this vulnerability, available from the WordPress Download Web page at http://wordpress.org/download/ |
| Related URL |
(CVE) |
| Related URL |
(SecurityFocus) |
| Related URL |
(ISS) |
|