Description
Multiple cross-site scripting (XSS) vulnerabilities in the mail_to helper in Ruby on Rails before 2.3.11, and 3.x before 3.0.4, when javascript encoding is used, allow remote attackers to inject arbitrary web script or HTML via a crafted (1) name or (2) email value.
Remediation
References
Related Vulnerabilities
WordPress Plugin AgentEasy Properties Cross-Site Scripting (1.0.4)
WordPress Plugin Advance Search for WooCommerce Cross-Site Scripting (1.0.9)
WordPress 4.2.x Same Origin Method Execution (SOME) Vulnerability (4.2 - 4.2.7)
WordPress Plugin WooCommerce Checkout Manager Cross-Site Request Forgery (4.3)