WordPress Cross-Site Scripting

OWASP 2013-A9 OWASP 2017-A9 OWASP 2021-A6 PCI v3.2-6.5.7 OWASP PC-C4 CAPEC-19 CWE-79 HIPAA-164.308(a) ISO27001-A.14.2.5 WASC-08 WSTG-INPV-01

Many servers use WordPress version 4.4-4.8.1, which is vulnerable to a Cross-Site Scripting (XSS) in oEmbed. An unauthenticated attacker can inject JavaScript code into WordPress comments. If these comments are improperly stored because of limitations on the MySQL TEXT data type. The script in the comment section will be triggered when the comment is viewed.

The oEmbed is an added extra hardening around allowed HTML for better security. The oEmbed is used for improved sandboxing.


The following code will get executed under this vulnerability.

    <b onmouseover=alert('Wufff!')>click me!</b>


Impact and Fixes

Latest Articles