CVE-2023-38000
MEDIUMWordPress 5.9-6.3.1 & Gutenberg <16.8.0 - Authenticated Stored XSS
Title source: llmDescription
Auth. Stored (contributor+) Cross-Site Scripting (XSS) vulnerability in WordPress core 6.3 through 6.3.1, from 6.2 through 6.2.2, from 6.1 through 6.1.3, from 6.0 through 6.0.5, from 5.9 through 5.9.7 and Gutenberg plugin <= 16.8.0 versions.
References (3)
Core 3
Core References
Exploit, Third Party Advisory third-party-advisory
https://patchstack.com/articles/wordpress-core-6-3-2-security-update-technical-advisory?_s_id=cve
Scores
CVSS v3
6.5
EPSS
0.0035
EPSS Percentile
57.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Details
CWE
CWE-79
Status
published
Products (8)
Gutenberg Team/Gutenberg
< 16.8.0
wordpress/gutenberg
< 16.8.0
wordpress/wordpress
5.9 - 5.9.7
WordPress.org/WordPress
5.9 - 5.9.7
WordPress.org/WordPress
6.0 - 6.0.5
WordPress.org/WordPress
6.1 - 6.1.3
WordPress.org/WordPress
6.2 - 6.2.2
WordPress.org/WordPress
6.3 - 6.3.1
Published
Oct 13, 2023
Tracked Since
Feb 18, 2026