CVE Database
/

CVE-2022-43500

Back to search

CVE-2022-43500

Published: Dec 5, 2022

Modified: Apr 24, 2025

PUBLISHED

Description

Cross-site scripting vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to inject an arbitrary script. The developer also provides new patched releases for all versions since 3.7.

VendorProductVersions

WordPress.org

WordPress

affected
versions prior to 6.0.3

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now