WordPress 6.0.3 Security Update – 16 Vulnerabilities That Must Be Fixed

state-of-wordpress-security-in-2023

The WordPress 6.0.3 Security Update contains patches for many vulnerabilities, most of which are low in severity or require a highly privileged user account or additional vulnerable code to exploit.

We want to share these vulnerabilities so you know them and take action to avoid a potentially hacked site.

1. Authenticated (Contributor+) Stored Cross-Site Scripting via RSS Widget/Block
Affected Versions: WordPress Core < 6.0.3 & Gutenberg < 14.3.1
Researcher:  N/A
CVE ID: Pending
CVSS Score: 6.4(Medium)
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Fully Patched Version: 6.0.3
Changeset: https://core.trac.wordpress.org/changeset/54543

A contributor-level attacker could create a page on a site they controlled that returned an error code and a malicious script in the Content-Type response header. 

2. Authenticated Stored Cross-Site Scripting via Search Block
Affected Versions: WordPress Core < 6.0.3 & Gutenberg < 14.3.1
Researcher: Alex Concha
CVE ID: Pending
CVSS Score: 6.4(Medium)
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Fully Patched Version: 6.0.3
Changeset: https://core.trac.wordpress.org/changeset/54543

It is possible for users that can edit posts to inject malicious JavaScript via the Search Block’s Text color and Background color attributes. 

Description: Authenticated Stored Cross-Site Scripting via Featured Image Block
Affected Versions: WordPress Core < 6.0.3 & Gutenberg < 14.3.1
Researcher: N/A
CVE ID: Pending
CVSS Score: 6.4(Medium)
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Fully Patched Version: 6.0.3
Changeset: https://core.trac.wordpress.org/changeset/54543

Pre-Orders for Woocommerce

4 Models
Get Presales
in a Comprehensive way

Related Blogs
WordPress Website Security Protocols Standard Operating Procedure (SOP)

Security Measures You Need to Consider When Managing a WordPress Website In your ongoing commitment to safeguarding digital assets and enhancing website security, we are implementing comprehensive security protocols for…

Who Needs a WooCommerce Order Delivery Date & Pickup Plugin

The WooCommerce Order Delivery Date & Pickup Pro plugin is designed to cater to a wide range of users, particularly those who run retail stores or e-commerce platforms that involve…

Why You Need the WooCommerce Brands Plugin

The WooCommerce Brands plugin adds brand functionality to your WooCommerce store, allowing you to organize and showcase products by their manufacturers, designers, or brands. This functionality provides several benefits and…

Best WooCommerce Pre-order Plugins Free and Paid

Selecting the right plugin when incorporating pre-order functionality into your WooCommerce store is pivotal. The landscape of pre-order plugins is diverse, offering a range of features across free and premium…