Description
"Genericons are vector icons embedded in a webfont designed to be clean and simple keeping with a generic aesthetic."
The Genericons package includes a file called example.html which has been found to be vulnerable to a DOM-based XSS vulnerability. This package is included in various WordPress plugins and themes. For example is included in the TwentyFifteen theme (installed by default) and the very popular JetPack plugin.
Remediation
Remove the example.html file located in the genericons directory.
References
WordPress 4.2.2 Security and Maintenance Release
Related Vulnerabilities
WordPress Plugin Helpful Cross-Site Scripting (4.4.58)
WordPress Plugin Total Sales For Woocommerce Cross-Site Scripting (1.1)
WordPress Plugin Gallery-Video Gallery and Youtube Gallery Cross-Site Scripting (1.2.4)
WordPress Plugin Backlink Rechecker Multiple Cross-Site Scripting Vulnerabilities (1.2.1)
WordPress Plugin Advance Search for WooCommerce Cross-Site Scripting (1.0.9)