In affected versions of WordPress, users with low privileges (like contributors and authors) can use the embed block in a certain way to inject unfiltered HTML in the block editor. When affected posts are viewed by a higher privileged user, this could lead to script execution in the editor/wp-admin. This has been patched in version 5.4.2, along with all the previously affected versions via a minor release (5.3.4, 5.2.7, 5.1.6, 5.0.10, 4.9.15, 4.8.14, 4.7.18, 4.6.19, 4.5.22, 4.4.23, 4.3.24, 4.2.28, 4.1.31, 4.0.31, 3.9.32, 3.8.34, 3.7.34).
{
"versions": [
{
"introduced": "3.7"
},
{
"fixed": "3.7.34"
},
{
"introduced": "3.8"
},
{
"fixed": "3.8.34"
},
{
"introduced": "3.9"
},
{
"fixed": "3.9.32"
},
{
"introduced": "4.0"
},
{
"fixed": "4.0.31"
},
{
"introduced": "4.1"
},
{
"fixed": "4.1.31"
},
{
"introduced": "4.2"
},
{
"fixed": "4.2.28"
},
{
"introduced": "4.3"
},
{
"fixed": "4.3.24"
},
{
"introduced": "4.4"
},
{
"fixed": "4.4.23"
},
{
"introduced": "4.5"
},
{
"fixed": "4.5.22"
},
{
"introduced": "4.6"
},
{
"fixed": "4.6.19"
},
{
"introduced": "4.7"
},
{
"fixed": "4.7.18"
},
{
"introduced": "4.8"
},
{
"fixed": "4.8.14"
},
{
"introduced": "4.9"
},
{
"fixed": "4.9.15"
},
{
"introduced": "5.0"
},
{
"fixed": "5.0.10"
},
{
"introduced": "5.1"
},
{
"fixed": "5.1.6"
},
{
"introduced": "5.2"
},
{
"fixed": "5.2.7"
},
{
"introduced": "5.4"
},
{
"fixed": "5.4.2"
}
]
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-4046.json"
[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "31"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "32"
}
]
}
]