VID |
210282 |
Severity |
30 |
Port |
80, ... |
Protocol |
TCP |
Class |
CGI |
Detailed Description |
WordPress versions 6.0 to 6.5.5 are affected by one or more vulnerabilities:
- A cross-site scripting (XSS) vulnerability affecting the HTML API. - A cross-site scripting (XSS) vulnerability affecting the Template Part block. - A path traversal issue affecting sites hosted on Windows.
* References: https://wordpress.org/download/releases/ https://wordpress.org/news/2024/06/wordpress-6-5-5/ https://wordpress.org/documentation/wordpress-version/version-6-5-5/
* Platforms Affected: WordPress prior equal to 6.5.5 Any operating system Any version |
Recommendation |
Upgrade to the version (6.5.5 or later) fixed this vulnerability, available from the WordPress Download Web page at http://wordpress.org/download/ |
Related URL |
(CVE) |
Related URL |
(SecurityFocus) |
Related URL |
(ISS) |
|