CVE-2024-31111
WordPress Core < 6.5.5 - Cross Site Scripting (XSS) vulnerability
CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Automattic WordPress allows Stored XSS.This issue affects WordPress: from 6.5 through 6.5.4, from 6.4 through 6.4.4, from 6.3 through 6.3.4, from 6.2 through 6.2.5, from 6.1 through 6.1.6, from 6.0 through 6.0.8, from 5.9 through 5.9.9.
| CWE | CWE-79 |
| Vendor | automattic |
| Product | wordpress |
| Ecosystems | |
| Industries | WebMedia |
| Published | Jun 25, 2024 |
| Last Updated | Apr 28, 2026 |
Stay Ahead of the Next One
Get instant alerts for automattic wordpress
Be the first to know when new medium vulnerabilities affecting automattic wordpress are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
Low
Affected Versions
Automattic / WordPress
6.5 ≤ 6.5.4 6.4 ≤ 6.4.4 6.3 ≤ 6.3.4 6.2 ≤ 6.2.5 6.1 ≤ 6.1.6 6.0 ≤ 6.0.8 5.9 ≤ 5.9.9
References
Credits
Rafie Muhammad (Patchstack)