High severity7.6NVD Advisory· Published Sep 9, 2021· Updated Jun 17, 2026
CVE-2021-39202
CVE-2021-39202
Description
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions the widgets editor introduced in WordPress 5.8 beta 1 has improper handling of HTML input in the Custom HTML feature. This leads to stored XSS in the custom HTML widget. This has been patched in WordPress 5.8. It was only present during the testing/beta phase of WordPress 5.8.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:wordpress:wordpress:5.8:beta1:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:wordpress:wordpress:5.8:beta1:*:*:*:*:*:*
- cpe:2.3:a:wordpress:wordpress:5.8:beta2:*:*:*:*:*:*
- (no CPE)range: <5.8
- Range: 5.8 beta 1
Patches
Vulnerability mechanics
References
2- github.com/WordPress/wordpress-develop/security/advisories/GHSA-fr6h-3855-j297nvdThird Party Advisory
- hackerone.com/reports/1222797nvdPermissions Required
News mentions
0No linked articles in our index yet.