github.com
https://github.com/WordPress/wordpress-develop/commit/0977c0d6b241479ecedfe19e96be69f727c3f81f CVE-2020-4047
MEDIUM
Authenticated XSS via media attachment page in WordPress
Record summary
CVE-2020-4047 has a selected CVSS score of 6.8 (medium).
Description
In affected versions of WordPress, authenticated users with upload permissions (like authors) are able to inject JavaScript into some media file attachment pages in a certain way. This can lead to script execution in the context of a higher privileged user when the file is viewed by them. This has been patched in version 5.4.2, along with all the previously affected versions via a minor release (5.3.4, 5.2.7, 5.1.6, 5.0.10, 4.9.15, 4.8.14, 4.7.18, 4.6.19, 4.5.22, 4.4.23, 4.3.24, 4.2.28, 4.1.31, 4.0.31, 3.9.32, 3.8.34, 3.7.34).
Description source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
wordpress-developBrowse WordPress / wordpress-develop | CVE List | >= 5.4.0, < 5.4.2 | affected |
| >= 5.3.0, < 5.3.4 | affected | ||
| >= 5.2.0, < 5.2.7 | affected | ||
| >= 5.1.0, < 5.1.6 | affected | ||
| >= 5.0.0, < 5.0.10 | affected | ||
| >= 4.9.0, < 4.9.15 | affected | ||
| >= 4.8.0, < 4.8.14 | affected | ||
| >= 4.7.0, < 4.7.18 | affected | ||
| >= 4.6.0, < 4.6.19 | affected | ||
| >= 4.5.0, < 4.5.22 | affected | ||
| >= 4.4.0, < 4.4.23 | affected | ||
| >= 4.3.0, < 4.3.24 | affected | ||
| Showing 12 of 18 version ranges | |||
References
8github.comConfirmation
https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-8q2w-5m27-wm27 [debian-lts-announce] 20200701 [SECURITY] [DLA 2269-1] wordpress security updatemailing list
https://lists.debian.org/debian-lts-announce/2020/07/msg00000.html [debian-lts-announce] 20200911 [SECURITY] [DLA 2371-1] wordpress security updatemailing list
https://lists.debian.org/debian-lts-announce/2020/09/msg00011.html FEDORA-2020-bbedd29391Vendor advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/773N2ZV7QEMBGKH6FBKI6Q5S3YJMW357 FEDORA-2020-8447a3e195Vendor advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ODNHXVJS25YVWYQHOCICXTLIN5UYJFDN wordpress.org
https://wordpress.org/news/2020/06/wordpress-5-4-2-security-and-maintenance-release DSA-4709Vendor advisory
https://www.debian.org/security/2020/dsa-4709