WordPress wp_get_attachment_link XSS Vulnerability (CVE-2016-5834)
WordPress wp_get_attachment_link XSS Vulnerability (CVE-2016-5834)
Release date:
Updated on:
Affected Systems:
WordPress <= 4.5.2
Description:
CVE (CAN) ID: CVE-2016-5834
WordPress is a blog platform developed in PHP.
A cross-site scripting vulnerability exists in the wp-uplodes/post-template.php/wp_get_attachment_link function of WordPress versions earlier than WordPress 4.5.3. Attackers can inject arbitrary Web scripts or HMTL by creating an attachment name.
<* Source: Jouko Pynn & #246; nen
Divyesh Prajapati
*>
Suggestion:
Vendor patch:
WordPress
---------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://codex.wordpress.org/Version_4.5.3
Https://wordpress.org/news/2016/06/wordpress-4-5-3/
This article permanently updates the link address: