Skip to content

Known CVE

WordPress Core <6.5.2 - Cross-Site Scripting

WordPress Core is vulnerable to Stored Cross-Site Scripting via user display names in the Avatar block in various versions up to 6.5.2 due to insufficient output escaping on the display name.

CVE-2024-4439

High2024CVSS 7.2CWE-80

wpscan · xss · wp · wordpress · footnote · sxss · post · vuln

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website