Description
Before version 4.8.2, WordPress was vulnerable to a cross-site scripting attack via shortcodes in the TinyMCE visual editor.
Remediation
References
Related Vulnerabilities
WordPress Plugin WooCommerce Dynamic Pricing & Discounts Multiple Vulnerabilities (2.4.1)
Envoy mishandles dropped and truncated datagrams Issue (CVE-2020-35471)
WordPress Plugin CP Contact Form with PayPal Cross-Site Scripting (1.2.98)
Sqlite Other Vulnerability (CVE-2022-46908)
WordPress Plugin Shortcode for Font Awesome Cross-Site Scripting (1.4)