Description
WordPress before 5.5.2 mishandles embeds from disabled sites on a multisite network, as demonstrated by allowing a spam embed.
Remediation
References
Related Vulnerabilities
WordPress Plugin Activity Log Multiple Cross-Site Scripting Vulnerabilities (2.3.2)
WordPress Plugin Slider Hero with Animation, Video Background Cross-Site Scripting (8.4.3)
WordPress Plugin WP Survey Plus Security Bypass (1.0)
MediaWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-2935)