Korean
<< Back
VID 210282
Severity 30
Port 80, ...
Protocol TCP
Class CGI
Detailed Description WordPress versions 6.0 to 6.5.5 are affected by one or more vulnerabilities:

- A cross-site scripting (XSS) vulnerability affecting the HTML API.
- A cross-site scripting (XSS) vulnerability affecting the Template Part block.
- A path traversal issue affecting sites hosted on Windows.

* References:
https://wordpress.org/download/releases/
https://wordpress.org/news/2024/06/wordpress-6-5-5/
https://wordpress.org/documentation/wordpress-version/version-6-5-5/

* Platforms Affected:
WordPress prior equal to 6.5.5
Any operating system Any version
Recommendation Upgrade to the version (6.5.5 or later) fixed this vulnerability, available from the WordPress Download Web page at http://wordpress.org/download/
Related URL (CVE)
Related URL (SecurityFocus)
Related URL (ISS)