WordPress MediaElement Cross-Site Scripting

Published on 26 Jun 2022
Vulnerability

Cross-site Scripting (XSS) is a client-side code injection attack where an attacker can execute malicious scripts into a website or web application. The old version of WordPress(3.7-4.9.1) is vulnerable to the Cross-Site Scripting vulnerability. It was discovered in the Flash fallback files in MediaElement. It is a library that is included with WordPress. An attacker will be able to inject malicious HTML and script code into the web application. The aftermath of this vulnerability includes altering the appearance and will widen the chance for a successful attack against end users. An attacker can misuse this vulnerability to execute malicious script code into the browser. This may allow the attacker to steal cookie-based authentication credentials.

The WordPress before the version 4.9.2 had XSS in the Flash fallback files in MediaElement (under wp-includes/js/mediaelement). This vulnerability was found in the Flash fallback files in MediaElement. MediaElement is a library that is included with WordPress. Flash files are not being used by most use cases, it has been removed from WordPress.

Impact and Fixes

Sooraj V Nair
Written by
Cyber Security Engineer

Sooraj was probably the kid who opened up a remote control just to see what was inside, then had to figure out how to put it back together before anyone noticed. That curiosity eventually found its way into cybersecurity, where breaking things is actually part of the job description. Today, he explores vulnerabilities, analysis threats, and helps build safer digital spaces. His favourite question remains the same: “What happens if I try this?”

Experience the Beagle Security platform
Unlock one full penetration test and all Advanced plan features free for 14 days
4.8 on G2 • ISO 27001 certified
See How Beagle Security Works
No credit card • No setup required
Launch interactive demo