Medium 5.9
2026-03-10
WordPress <= 6.9.1 - Authenticated (Author+) XML External Entity Injection via getID3 Library Media Upload
WordPress <= 6.9.1 - Authenticated (Author+) XML External Entity Injection via getID3 Library Media Upload
CVE-2024-32111
CVE-2024-31111
CVE-2024-6307
WordPress is vulnerable to Cross Site Scripting (XSS)
CVE-2024-4439