Description

WordPress processes shortcodes in user-generated content on block themes. This could allow an attacker to execute shortcodes via submitting comments or other content, allowing them to exploit vulnerabilities that typically require higher permissions. WordPress versions 6.0.x ranging from 6.0 and up to (and including) 6.0.4 are vulnerable.

Remediation

Update to WordPress version 6.0.5 or latest

References

Related Vulnerabilities