CVE-2016-4567

medium
Published 2016-05-22 · Modified 2024-04-25
CVSS v3
6.1
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS v2
4.3
VIR risk
6.1

Description

MediaElement Vulnerable to Reflected XSS

Predictions

Exploit likelihood
71%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2016-4567

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://wordpress.org/news/2016/05/wordpress-4-5-2/

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://github.com/johndyer/mediaelement/commit/34834eef8ac830b9145df169ec22016a4350f06e

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://github.com/johndyer/mediaelement/blob/master/changelog.md

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://core.trac.wordpress.org/changeset/37371

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://codex.wordpress.org/Version_4.5.2

OS impact

OSVersionStatusFixed in
debian debianbookwormaffected
debian debianbullseyeaffected
debian debianforkyaffected
debian debiansidaffected
debian debiantrixieaffected

Package impact

EcosystemPackageVulnerableFixed
npm npmmediaelement<2.11.12.11.1
php Packagistcontao-components/mediaelement>=2.14.2,<2.21.12.21.1
php Packagistcontao/core>=3.0.0,<3.5.153.5.15

Application impact

VendorProductVersionsFixed
mediaelementjsmediaelement.js{"endIncluding":"2.20.1"}
wordpresswordpress{"endIncluding":"4.5.1"}

References

CWEs

CWE-79

Verify integrity in audit chain (admin only). AS-IS.