Description
WordPress is prone to multiple prototype pollution vulnerabilities. Exploiting these issues could allow an attacker to inject key/value �properties� into JavaScript objects, potentially allowing for execution of arbitrary JavaScript in a user�s session if they can trick that user into clicking a link. WordPress versions 5.7.x ranging from 5.7 and up to (and including) 5.7.5 are vulnerable.
Remediation
Update to WordPress version 5.7.6 or latest
References
https://github.com/BlackFan/client-side-prototype-pollution/blob/master/pp/jquery-query-object.md
https://github.com/WordPress/gutenberg/pull/39365/files
https://wordpress.org/support/wordpress-version/version-5-7-6/
Related Vulnerabilities
Oracle Database Server CVE-2008-1819 Vulnerability (CVE-2008-1819)
WordPress Plugin FunCaptcha-Anti-Spam CAPTCHA Cross-Site Request Forgery (0.3.2)
WordPress Plugin Export any WordPress data to XML/CSV Cross-Site Scripting (1.3.0)
WordPress Plugin Google Drive for WordPress Information Disclosure (2.2)
WordPress Plugin Simple Download Monitor Cross-Site Scripting (3.5.3)