Opened 3 years ago
Closed 3 years ago
#57524 closed defect (bug) (wontfix)
Bug when submitting a post using the WordPress Editor
| Reported by: | pmk1071 | Owned by: | |
|---|---|---|---|
| Priority: | normal | Milestone: | |
| Component: | Posts, Post Types | Version: | |
| Severity: | critical | Keywords: | has-screenshots |
| Cc: | Focuses: |
Description
I have found a vulnerability when utilizing the WordPress Editor. I would like to be able to discuss this after I am able to reach an offer that is worth its value.
Thanks,
Paulson Kimani
Attachments (1)
Change History (3)
#1
@
3 years ago
- Keywords has-screenshots added
- Severity blocker → critical
When I submit a Word document using the default post editor from a previous version of Microsoft Word, it allows HTML tags to be represented in the form.
#2
@
3 years ago
- Keywords needs-patch removed
- Milestone Awaiting Review
- Resolution → wontfix
- Status new → closed
- Version 6.1.1
Welcome to Trac, @pmk1071, and thank you for the report!
Unfiltered HTML in titles, posts, and comments is allowed by certain roles in WordPress, so this is a feature, and not a bug. (But I agree that it can seem odd 😂.) I'll close this ticket, since the behavior in question is expected.
For future reference, please keep in mind that Core Trac is used for non-security related bug reports. However, if you do come across a security issue in the future, please refer to the Reporting Security Vulnerabilities page for reporting guidelines. Thanks!
![(please configure the [header_logo] section in trac.ini)](/chrome/site/your_project_logo.png)
Note the opening and closing tags in the titles for the post names . It is reproducible and was not added afterwards.