Candidate: CVE-2019-20042 PublicDate: 2019-12-27 08:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-20042 https://core.trac.wordpress.org/changeset/46894/trunk https://github.com/WordPress/wordpress-develop/commit/1f7f3f1f59567e2504f0fbebd51ccf004b3ccb1d https://wordpress.org/news/2019/12/wordpress-5-3-1-security-and-maintenance-release/ https://blog.ripstech.com/filter/vulnerabilities/ https://wpvulndb.com/vulnerabilities/9975 Description: In wp-includes/formatting.php in WordPress 3.7 to 5.3.0, the function wp_targeted_link_rel() can be used in a particular way to result in a stored cross-site scripting (XSS) vulnerability. This has been patched in WordPress 5.3.1, along with all the previous WordPress versions from 3.7 to 5.3 via a minor release. Ubuntu-Description: Notes: Mitigation: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=946905 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N [6.1 MEDIUM] Patches_wordpress: upstream_wordpress: released (5.3.2+dfsg1-1) precise/esm_wordpress: DNE trusty_wordpress: ignored (out of standard support) trusty/esm_wordpress: DNE xenial_wordpress: ignored (end of standard support, was needs-triage) bionic_wordpress: needs-triage disco_wordpress: ignored (reached end-of-life) eoan_wordpress: ignored (reached end-of-life) focal_wordpress: not-affected (5.3.2+dfsg1-1) groovy_wordpress: not-affected (5.3.2+dfsg1-1) hirsute_wordpress: not-affected (5.3.2+dfsg1-1) impish_wordpress: not-affected (5.3.2+dfsg1-1) jammy_wordpress: not-affected (5.3.2+dfsg1-1) devel_wordpress: not-affected (5.3.2+dfsg1-1)