SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-21662

Low-privileged authenticated users (like author) in WordPress core are able to execute JavaScript/perform stored XSS attack, which can affect high-privileged users.

MEDIUM 5.4EPSS 64.5%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 64.5%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.

Description

WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Low-privileged authenticated users (like author) in WordPress core are able to execute JavaScript/perform stored XSS attack, which can affect high-privileged users. This has been patched in WordPress version 5.8.3. Older affected versions are also fixed via security release, that go back till 3.7.37. We strongly recommend that you keep auto-updates enabled. There are no known workarounds for this issue.

CVSS 3.1
5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS
64.53% probability · 99th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
wordpress/wordpress · debian/debian linux
Source
security-advisories@github.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.