Skip to content

WordPress: Authenticated self-XSS via theme uploads

Low
ehti published GHSA-87h4-phjv-rm6p Jun 12, 2020

Package

No package listed

Affected versions

3.7 - 5.4.1

Patched versions

5.4.2

Description

Impact

When uploading themes, the name of the theme folder can be crafted in a way that could lead to JavaScript execution in /wp-admin on the themes page. This does require an admin to upload the theme, and is low severity self-XSS.

Patches

This has been patched in WordPress 5.4.2, along with all the previously affected versions via a minor release. Automatic updates are enabled by default for minor releases and we strongly recommend that you keep them enabled.

For more information

If you have any questions or comments about this advisory:

Severity

Low

CVE ID

CVE-2020-4049

Weaknesses

No CWEs