Vulnerability record · CVE-2022-21662 · published 6 January 2022
CVE-2022-21662: WordPress core stored XSS by low-privileged authenticated users
Wordpress · Wordpress
WordPress core allows low-privileged authenticated users such as authors to store JavaScript that executes in the browser of higher-privileged users, a stored cross-site scripting flaw (CWE-79). It matters because a low-trust account can reach administrative sessions, and the vendor states there are no known workarounds. The issue is patched in WordPress 5.8.3, with backports to 3.7.37 and later security releases.
Description
WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Low-privileged authenticated users (like author) in WordPress core are able to execute JavaScript/perform stored XSS attack, which can affect high-privileged users. This has been patched in WordPress version 5.8.3. Older affected versions are also fixed via security release, that go back till 3.7.37. We strongly recommend that you keep auto-updates enabled. There are no known workarounds for this issue.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Automated analysis
medium priorityCVSS rates it medium (5.4) and it requires an authenticated low-privileged account plus victim interaction, though the high EPSS percentile and privileged-victim target raise concern.
What it is
WordPress core allows low-privileged authenticated users such as authors to store JavaScript that executes in the browser of higher-privileged users, a stored cross-site scripting flaw (CWE-79). It matters because a low-trust account can reach administrative sessions, and the vendor states there are no known workarounds. The issue is patched in WordPress 5.8.3, with backports to 3.7.37 and later security releases.
Impact
An attacker with a low-privileged account can run script in a higher-privileged user's session, enabling session or data theft and actions performed as that user. The CVSS vector rates scope changed with low confidentiality and integrity impact, so full site takeover is not guaranteed by the record alone.
Attack surface
Reached over the network through WordPress content handling; the attacker needs an authenticated low-privileged account, and a higher-privileged user must view the crafted content, so user interaction is required. No unauthenticated path is described.
Exploitation
Not listed in CISA KEV and no reference is tagged as exploit code, but EPSS is high at 0.64529 (99.2nd percentile), indicating elevated likelihood of exploitation activity. The record does not confirm public exploit availability.
What to do
- Update WordPress core to 5.8.3 or later; for older branches apply the corresponding security release back to 3.7.37.
- Keep WordPress auto-updates enabled as the vendor recommends, since no workaround exists.
- Update packaged WordPress on Debian and Fedora systems per DSA-5039 and the Fedora package announcements.
- Reduce the number of author-level and similar low-privileged accounts and review their capabilities.
- Apply output encoding and content sanitization controls on any custom code that renders user-supplied content.
Detection
- Review posts, comments and other stored content created by low-privileged accounts for injected script or unexpected HTML.
- Monitor web logs for requests containing script payloads in parameters tied to content creation or editing.
- Alert on administrative sessions that follow recent views of content authored by low-privileged users.
- Check WordPress version reporting across the estate to find hosts still below 5.8.3 or unpatched backport levels.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2022-21662 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-21662), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.