Description
In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
Remediation
References
Related Vulnerabilities
WordPress Plugin Frontend File Manager Arbitrary File Upload (3.9)
WordPress Plugin BuddyPress Extended Friendship Request Cross-Site Scripting (1.0.1)
XWiki Weak Password Recovery Mechanism for Forgotten Password Vulnerability (CVE-2022-23619)
WordPress Plugin Bitcoin Faucet Cross-Site Scripting (1.0.12)
WordPress Plugin Yakadanda Google+ Hangout Events Cross-Site Scripting (0.3.7)