CVE-2024-31111: Automattic WordPress

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Automattic WordPress allows Stored XSS.This issue affects WordPress: from 6.5 through 6.5.4, from 6.4 through 6.4.4, from 6.3 through 6.3.4, from 6.2 through 6.2.5, from 6.1 through 6.1.6, from 6.0 through 6.0.8, from 5.9 through 5.9.9.

Affected products

  • Automattic WordPress: from 6.5, up to and including 6.5.4; from 6.4, up to and including 6.4.4; from 6.3, up to and including 6.3.4; from 6.2, up to and including 6.2.5; from 6.1, up to and including 6.1.6; from 6.0, up to and including 6.0.8; …

Published 2024-06-25. Last modified 2026-06-17.