The emoji loader read its configuration from an element resolved with document.getElementById( ‘wp-emoji-settings’ ). Post content authored by a Contributor-level user can inject an element with that id (DOM clobbering), so the loader parses attacker-controlled JSON, including the script URLs it subsequently loads. This lets a Contributor execute arbitrary JavaScript in the browser of any visitor who views the post.
This vulnerability affects the following application versions:
- WordPress 6.9
- WordPress 6.9.1
- WordPress 6.9.2
- WordPress 6.9.3
- WordPress 6.9.4
- WordPress 6.9.5
- WordPress 7.0
- WordPress 7.0.1
- WordPress 7.0.2