Input validation vulnerability in WordPress 5.6.11

WordPress Core, the software used to create and manage websites, is vulnerable to a type of attack called Reflected Cross-Site Scripting. This vulnerability exists in versions 5.6 to 6.3.1 and is caused by an issue with the way parameters are handled when requesting application passwords. Attackers could take advantage of this vulnerability by injecting malicious web scripts into pages and convincing a user to click on a link or accept or reject an application password. If successful, these scripts would then be executed.

Detected in:

WordPress fixed vulnerable versions: >= 5.6 <= 5.6.11

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.