Description
Multiple cross-site scripting (XSS) vulnerabilities in wp-includes/class-wp-theme.php in WordPress before 4.4.1 allow remote attackers to inject arbitrary web script or HTML via a (1) stylesheet name or (2) template name to wp-admin/customize.php.
Remediation
References
Related Vulnerabilities
MySQL CVE-2016-0648 Vulnerability (CVE-2016-0648)
WordPress Plugin Image Gallery-Responsive Photo Gallery Cross-Site Scripting (2.0.5)
WordPress Plugin Super Interactive Maps for WordPress SQL Injection (2.1)
WordPress Plugin One Click SSL Cross-Site Request Forgery (1.4.6)
Dot CMS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-3688)