Security Research

CVE-2024-4439 WordPress Core Unauthenticated Stored XSS: Block Editor rendering chain

#Vulnerability Analysis#Code Audit#Web Security
Dark dossier of WordPress Block Editor and script injection

WordPress Core versions prior to 6.5 do not sufficiently filter content when rendering in the Block Editor. An attacker-crafted post can trigger an unauthenticated stored XSS.

Unlock to view this content.