Description
In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could modify new comments made by users with greater privileges, possibly causing XSS.
Remediation
References
Related Vulnerabilities
Oracle JRE CVE-2024-20919 Vulnerability (CVE-2024-20919)
phpMyFAQ Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2017-15735)
WordPress Plugin Rich Table of Contents Cross-Site Scripting (1.3.7)
XWiki Incorrect Authorization Vulnerability (CVE-2023-32069)
Ruby Improper Input Validation Vulnerability (CVE-2008-3790)