Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Debian 11: WordPress Critical XSS Issues DLA-4358-1 CVE-2024-6307

debian lts
Calendar Grey November 3, 2025
Dist Debian Esm H88
Multiple vulnerabilities in WordPress threaten user security through improper sanitization. Update recommended!
Several security vulnerabilities have been discovered in Wordpress, a popular content management framework

Summary

CVE-2024-6307

WordPress Core is vulnerable to stored Cross-Site Scripting via
the HTML API due to insufficient input sanitization and output
escaping on URLs. This makes it possible for authenticated
attackers, with contributor-level access and above, to inject
arbitrary web scripts in pages that will execute whenever a user
accesses an injected page.

CVE-2024-31111

Improper neutralization of input during web gage generation (XSS or
"Cross-site Scripting") vulnerability in Automattic WordPress allows
Stored XSS.

CVE-2025-58246

Insertion of sensitive information into sent data vulnerability in
WordPress allows retrieval of embedded sensitive data.

CVE-2025-58674

Improper neutralization of input during web page generation
("Cross-site Scripting") vulnerability in WordPress allows
Stored XSS.

For Debian 11 bullseye, these problems have been fixed in version
5.7.14+dfsg1-0+deb11u1.

We recommend that you upgrade your wordpress packages.

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

Package: wordpress
Version: 5.7.14+dfsg1-0+deb11u1
CVE ID: CVE-2024-6307 CVE-2024-31111 CVE-2025-58246
Debian Bug: 1074486 1117047

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here