Description
Cross-site scripting (XSS) vulnerability in plupload.flash.swf in Plupload before 2.1.9, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via a Same-Origin Method Execution (SOME) attack.
Remediation
References
Related Vulnerabilities
Oracle HTTP Server CVE-2021-2315 Vulnerability (CVE-2021-2315)
Piwigo Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2019-13363)
WordPress Plugin YITH Maintenance Mode Cross-Site Scripting (1.1.4)
WordPress Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-6514)