CVE-2023-38000

MEDIUM

WordPress 5.9-6.3.1 & Gutenberg <16.8.0 - Authenticated Stored XSS

Title source: llm
STIX 2.1

Description

Auth. Stored (contributor+) Cross-Site Scripting (XSS) vulnerability in WordPress core 6.3 through 6.3.1, from 6.2 through 6.2.2, from 6.1 through 6.1.3, from 6.0 through 6.0.5, from 5.9 through 5.9.7 and Gutenberg plugin <= 16.8.0 versions.

Scores

CVSS v3 6.5
EPSS 0.0035
EPSS Percentile 57.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L

Details

CWE
CWE-79
Status published
Products (8)
Gutenberg Team/Gutenberg < 16.8.0
wordpress/gutenberg < 16.8.0
wordpress/wordpress 5.9 - 5.9.7
WordPress.org/WordPress 5.9 - 5.9.7
WordPress.org/WordPress 6.0 - 6.0.5
WordPress.org/WordPress 6.1 - 6.1.3
WordPress.org/WordPress 6.2 - 6.2.2
WordPress.org/WordPress 6.3 - 6.3.1
Published Oct 13, 2023
Tracked Since Feb 18, 2026