Opened 5 years ago
Closed 5 years ago
#48840 closed defect (bug) (invalid)
Stored Xss on WordPress
Reported by: |
|
Owned by: | |
---|---|---|---|
Milestone: | Priority: | normal | |
Severity: | normal | Version: | 5.4 |
Component: | Editor | Keywords: | |
Focuses: | Cc: |
Description
I tried to make a block in the post editor with an html block, then put a payload on the block, after I post and click it will appear an alert on the wordpress website.
Attachments (1)
Change History (2)
Note: See
TracTickets for help on using
tickets.
Hi there, welcome to WordPress Trac!
When writing the ticket you should have seen this notice:
Worth noting this is not a real security issue since administrators or editors are able to post arbitrary JavaScript.
If you think you have found a real security vulnerability, please head over to HackerOne, and do not post it here.
Thanks for your cooperation.