Input validation vulnerability in WordPress 6.8.2

WordPress Core, a popular website platform, has a security issue called Stored Cross-Site Scripting that affects all versions up to and including 6.8.2. This happens because the program doesn’t properly clean up user inputs and outputs, which can allow attackers to add harmful web scripts to pages. This could potentially harm users who visit those pages. Unfortunately, there is currently no solution available as the issue was accidentally revealed by a third-party. The WordPress team is aware of the problem and is working on a solution. However, they have decided to keep the details public until a patch is available. The risk to WordPress websites is low, and the security team is actively addressing the issue.

Detected in:

WordPress fixed vulnerable versions: >= * <= 4.7

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.