Description
In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute.
Remediation
References
Related Vulnerabilities
WordPress Plugin WordPress Landing Pages Multiple Unspecified Vulnerabilities (1.7.8)
WordPress 3.9.x Cross-Site Scripting Vulnerability (3.9 - 3.9.9)
PHP Other Vulnerability (CVE-2015-8866)
WordPress Plugin Popup Maker-Popup for opt-ins, lead gen, & more Multiple Vulnerabilities (1.17.1)
OpenSSL Improper Input Validation Vulnerability (CVE-2015-1787)