Description
In affected versions of WordPress, a cross-site scripting (XSS) vulnerability in the navigation section of Customizer allows JavaScript code to be executed. Exploitation requires an authenticated user. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3, 5.2.6, 5.1.5, 5.0.9, 4.9.14, 4.8.13, 4.7.17, 4.6.18, 4.5.21, 4.4.22, 4.3.23, 4.2.27, 4.1.30, 4.0.30, 3.9.31, 3.8.33, 3.7.33).
Remediation
References
Related Vulnerabilities
MySQL CVE-2020-2570 Vulnerability (CVE-2020-2570)
Oracle Database Server CVE-2020-2512 Vulnerability (CVE-2020-2512)
XWiki Improper Neutralization of Alternate XSS Syntax Vulnerability (CVE-2023-35158)
WordPress Plugin PWA for WP & AMP Unspecified Vulnerability (1.0.8)
WordPress Plugin CSS & JavaScript Toolbox SQL Injection (9.2)