BIT-wordpress-multisite-2023-38000

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/wordpress-multisite/BIT-wordpress-multisite-2023-38000.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-wordpress-multisite-2023-38000
Aliases
Published
2024-03-06T11:08:46.905Z
Modified
2025-05-20T10:02:07.006Z
Summary
Auth. Stored Cross-Site Scripting (XSS) vulnerability in WordPress core and Gutenberg plugin via Navigation Links Block
Details

Auth. Stored (contributor+) Cross-Site Scripting (XSS) vulnerability in WordPress core 6.3 through 6.3.1, from 6.2 through 6.2.2, from 6.1 through 6.1.3, from 6.0 through 6.0.5, from 5.9 through 5.9.7 and Gutenberg plugin <= 16.8.0 versions.

Database specific
{
    "cpes": [
        "cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*"
    ],
    "severity": "Medium"
}
References

Affected packages

Bitnami / wordpress-multisite

Package

Name
wordpress-multisite
Purl
pkg:bitnami/wordpress-multisite

Severity

  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
5.9.0
Fixed
5.9.8
Introduced
6.0.0
Fixed
6.0.6
Introduced
6.1.0
Fixed
6.1.4
Introduced
6.2.0
Fixed
6.2.3
Introduced
6.3.0
Fixed
6.3.2

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/wordpress-multisite/BIT-wordpress-multisite-2023-38000.json"