Name | CVE-2019-16781 |
Description | In WordPress before 5.3.1, authenticated users with lower privileges (like contributors) can inject JavaScript code in the block editor, which is executed within the dashboard. It can lead to an admin opening the affected post in the editor leading to XSS. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
References | DSA-4599-1 |
Debian Bugs | 946905 |
Vulnerable and fixed packages
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|
wordpress (PTS) | jessie, jessie (lts) | 4.1.35+dfsg-0+deb8u1 | fixed |
| stretch (security), stretch (lts), stretch | 4.7.23+dfsg-0+deb9u1 | fixed |
| buster (security), buster, buster (lts) | 5.0.21+dfsg1-0+deb10u1 | fixed |
| bullseye (security), bullseye | 5.7.11+dfsg1-0+deb11u1 | fixed |
| bookworm (security), bookworm | 6.1.6+dfsg1-0+deb12u1 | fixed |
| sid, trixie | 6.6.1+dfsg1-1 | fixed |
The information below is based on the following data on fixed versions.
Notes
[stretch] - wordpress <not-affected> (Vulnerable Block feature introduce in 5.0)
[jessie] - wordpress <not-affected> (Vulnerable Block feature introduce in 5.0)
https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-pg4x-64rh-3c9v
https://hackerone.com/reports/731301
https://wordpress.org/news/2019/12/wordpress-5-3-1-security-and-maintenance-release/