WordPress Core before 4.7 Stored XSS

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

As you might remember, we recently blogged about a critical [Content Injection Vulnerability in WordPress](https://blog.sucuri.net/2017/02/content-injection-vulnerability-wordpress-rest-api.html) which allowed attackers to [deface vulnerable websites](https://blog.sucuri.net/2017/02/wordpress-rest-api-vulnerability-abused-in-defacement-campaigns.html). While our original disclosure only described one vulnerability, we actually reported two to the WordPress team. As it turns out, it was possible to leverage the content injection issue to achieve a stored cross-site scripting attack. This issue was **[patched in WordPress 4.7.3](https://wordpress.org/news/2017/03/wordpress-4-7-3-security-and-maintenance-release/).** ### Are You at Risk? This vulnerability has been present in WordPress for quite a while, well before 4.7. Combined with the recent content injection vulnerability we found, it’s possible for a remote attacker to deface a random post on the site and store malicious...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息