---
title: "CVE-2021-39201"
canonical: "https://kb.cynergy.app/space/MD/923631891/CVE-2021-39201"
format: markdown
---
**Description**

Specific versions of [Debian Linux](https://cve.report/software/debian/debian_linux) from [Debian](https://cve.report/vendor/debian) contain the following vulnerability:

WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. The issue allows an authenticated but low-privileged user (like a contributor/author) to execute XSS in the editor. This bypasses the restrictions imposed on users who do not have permission to post `unfiltered_html`.

**Published On**

09/09/2021

**Updated On**

12/14/2021

**Trending**

FALSE

**CWE**

[CWE-79](http://cwe.mitre.org/data/definitions/79.html)

**Exploit**


**Mitigation:**

![image](media://e248d433-de6d-41ee-a6a0-d9f9d4da779a)

Cynergy has an automated mitigation capability that requires integration with your WAF provider.

Once integrated, you can request “Protect with WAF”

This will move the exposed asset behind WAF protection

<span style="color: #97a0af">**Note: **</span><span style="color: #97a0af">Policies configuration should be defined separately</span>

 

**Remediation**

- Patches This has been patched in WordPress 5.8 and will be pushed to older versions via minor releases (automatic updates). It's strongly recommended that you keep auto-updates enabled to receive the fix.
  

**References**

|  |  |  |
| --- | --- | --- |
| HackerOne | [http://hackerone.com](http://hackerone.com)   
<span style="color: #ffffff">**text/html**</span> | ![URL Logo]() |
| Debian -- Security Information -- DSA-4985-1 wordpress | [http://www.debian.org](http://www.debian.org)   
<span style="color: #ffffff">**Depreciated Link**</span>  
<span style="color: #ffffff">**text/html**</span> | ![URL Logo]() |
| Authenticated cross-site scripting (XSS) in WordPress editor · Advisory · WordPress/wordpress-develop · GitHub | [http://github.com](http://github.com)   
<span style="color: #ffffff">**text/html**</span> | ![URL Logo]() |