CVE-2024-6307
WordPress Core is vulnerable to stored Cross-Site Scripting via
the HTML API due to insufficient input sanitization and output
escaping on URLs. This makes it possible for authenticated
attackers, with contributor-level access and above, to inject
arbitrary web scripts in pages that will execute whenever a user
accesses an injected page.
CVE-2024-31111
Improper neutralization of input during web gage generation (XSS or
"Cross-site Scripting") vulnerability in Automattic WordPress allows
Stored XSS.
CVE-2025-58246
Insertion of sensitive information into sent data vulnerability in
WordPress allows retrieval of embedded sensitive data.
CVE-2025-58674
Improper neutralization of input during web page generation
("Cross-site Scripting") vulnerability in WordPress allows
Stored XSS.
For Debian 11 bullseye, these problems have been fixed in version
5.7.14+dfsg1-0+deb11u1.
We recommend that you upgrade your wordpress packages.
Get the latest Linux and open source security news straight to your inbox.