[Bug reporting] XSS vulnerabilty in wp_kses_bad_protocol in wp-includes/kses.php (CVE-2019-20041)

Author: seongil-wiCreated Sep 10, 2021Updated Sep 10, 2021

Hi

Our research team in KAIST WSP Lab found a known XSS vulnerability in the recent version of dockerlabs. In particular, the bug we report is a known bug by CVE-2019-20041.

wp_kses_bad_protocol in wp-includes/kses.php in WordPress before 5.3.1 mishandles the HTML5 colon named entity, allowing attackers to bypass input sanitization, as demonstrated by the javascript: substring.

Please check this line.

Thanks!