← Vulnerability feed

Vulnerability record · CVE-2022-21662 · published 6 January 2022

CVE-2022-21662: WordPress core stored XSS by low-privileged authenticated users

Wordpress · Wordpress

WordPress core allows low-privileged authenticated users such as authors to store JavaScript that executes in the browser of higher-privileged users, a stored cross-site scripting flaw (CWE-79). It matters because a low-trust account can reach administrative sessions, and the vendor states there are no known workarounds. The issue is patched in WordPress 5.8.3, with backports to 3.7.37 and later security releases.

5.4 CVSS 3.1 Medium EPSS 65% · top 0.8% CWE-79 · Cross-site scripting
5.4CVSS 3.1 base score, v2 3.5
65%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
12References
17 Jun 2026Last modified by NVD

Description

WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Low-privileged authenticated users (like author) in WordPress core are able to execute JavaScript/perform stored XSS attack, which can affect high-privileged users. This has been patched in WordPress version 5.8.3. Older affected versions are also fixed via security release, that go back till 3.7.37. We strongly recommend that you keep auto-updates enabled. There are no known workarounds for this issue.

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

medium priorityCVSS rates it medium (5.4) and it requires an authenticated low-privileged account plus victim interaction, though the high EPSS percentile and privileged-victim target raise concern.

What it is

WordPress core allows low-privileged authenticated users such as authors to store JavaScript that executes in the browser of higher-privileged users, a stored cross-site scripting flaw (CWE-79). It matters because a low-trust account can reach administrative sessions, and the vendor states there are no known workarounds. The issue is patched in WordPress 5.8.3, with backports to 3.7.37 and later security releases.

Impact

An attacker with a low-privileged account can run script in a higher-privileged user's session, enabling session or data theft and actions performed as that user. The CVSS vector rates scope changed with low confidentiality and integrity impact, so full site takeover is not guaranteed by the record alone.

Attack surface

Reached over the network through WordPress content handling; the attacker needs an authenticated low-privileged account, and a higher-privileged user must view the crafted content, so user interaction is required. No unauthenticated path is described.

Exploitation

Not listed in CISA KEV and no reference is tagged as exploit code, but EPSS is high at 0.64529 (99.2nd percentile), indicating elevated likelihood of exploitation activity. The record does not confirm public exploit availability.

What to do

  • Update WordPress core to 5.8.3 or later; for older branches apply the corresponding security release back to 3.7.37.
  • Keep WordPress auto-updates enabled as the vendor recommends, since no workaround exists.
  • Update packaged WordPress on Debian and Fedora systems per DSA-5039 and the Fedora package announcements.
  • Reduce the number of author-level and similar low-privileged accounts and review their capabilities.
  • Apply output encoding and content sanitization controls on any custom code that renders user-supplied content.

Detection

  • Review posts, comments and other stored content created by low-privileged accounts for injected script or unexpected HTML.
  • Monitor web logs for requests containing script payloads in parameters tied to content creation or editing.
  • Alert on administrative sessions that follow recent views of content authored by low-privileged users.
  • Check WordPress version reporting across the estate to find hosts still below 5.8.3 or unpatched backport levels.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-21662 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-32433Erlang/OTP SSH server missing authentication allows remote code executionErlang/OTP SSH servers before OTP-27.3.3, OTP-26.2.5.11 and OTP-25.3.2.20 mishandle SSH protocol messages, letting an unauthenticated attacker execut…KEVEPSS 99%analysed10.0CVE-2025-24201Apple WebKit out-of-bounds write allows sandbox escapeCVE-2025-24201 is an out-of-bounds write in Apple's WebKit that was addressed with improved checks. Maliciously crafted web content may break out of …KEVEPSS 3.8%analysed10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed9.8CVE-2026-63030WordPress REST API route confusion leads to SQL injection and RCEWordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 contain a REST API batch endpoint route confusion flaw (CWE-436). Chained with the author__not_in…KEVEPSS 10%analysed9.8CVE-2026-24061GNU Inetutils telnetd argument injection allows remote auth bypasstelnetd in GNU Inetutils through 2.7 fails to sanitize the USER environment variable, so a value such as "-f root" is passed as an argument to login …KEVEPSS 99%analysed9.8CVE-2025-39682Linux kernel TLS zero-length record handling flaw on rx_listThe Linux kernel TLS receive path mishandles zero-length records that arrive from the rx_list, breaking the assumption that a record type change cann…KEVEPSS 2.9%analysed9.8CVE-2025-24813Apache Tomcat Default Servlet path equivalence enables RCE and file disclosureApache Tomcat mishandles path equivalence for names containing an internal dot, letting a remote unauthenticated attacker write files through the Def…KEVEPSS 100%analysed9.8CVE-2024-9680Mozilla Firefox and Thunderbird use-after-free in Animation timelinesA use-after-free flaw in Animation timelines allows an attacker to execute code in the content process of Firefox and Thunderbird. Mozilla reports ex…KEVEPSS 23%analysed

Source: NIST National Vulnerability Database (record CVE-2022-21662), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.