Description
Before version 4.8.2, WordPress allowed Cross-Site scripting in the plugin editor via a crafted plugin name.
Remediation
References
Related Vulnerabilities
Oracle Database Server CVE-2007-5504 Vulnerability (CVE-2007-5504)
Magento Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2019-7874)
WordPress Plugin vSlider Multi Image Slider for WordPress Multiple Vulnerabilities (4.1.2)
Jenkins Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-2609)