Description
Before version 4.8.2, WordPress was susceptible to a Cross-Site Scripting attack in the link modal via a javascript: or data: URL.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP Plugin Manager (WPPM) Cross-Site Scripting (1.6.4.b)
WordPress Plugin WP-OliveCart Multiple Vulnerabilities (3.1.2)
WordPress Plugin Pixabay Images Multiple Vulnerabilities (2.3)
Grafana Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2022-21703)
Jboss EAP Improper Privilege Management Vulnerability (CVE-2019-14838)