The emoji loader read its configuration from an element resolved with document.getElementById( ‘wp-emoji-settings’ ). Post content authored by a Contributor-level user can inject an element with that id (DOM clobbering), so the loader parses attacker-controlled JSON, including the script URLs it subsequently loads. This lets a Contributor execute arbitrary JavaScript in the browser of any visitor who views the post.

This vulnerability affects the following application versions:

  • WordPress 6.9
  • WordPress 6.9.1
  • WordPress 6.9.2
  • WordPress 6.9.3
  • WordPress 6.9.4
  • WordPress 6.9.5
  • WordPress 7.0
  • WordPress 7.0.1
  • WordPress 7.0.2

Skriv et svar

Din e-mailadresse vil ikke blive publiceret. Krævede felter er markeret med *