Description
Multiple cross-site scripting (XSS) vulnerabilities in wp-admin/update-core.php in WordPress before 4.7.1 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) version header of a plugin.
Remediation
References
Related Vulnerabilities
WordPress Denial of Service Vulnerability (0.70 - 3.6.1)
WordPress Plugin WPML (WordPress Multilingual) Cross-Site Request Forgery (4.3.6)
WordPress Plugin WordPress Survey & Poll-Quiz, Survey and Poll Unspecified Vulnerability (1.5.8.5)
Liferay Portal Improper Authentication Vulnerability (CVE-2021-29047)
WordPress Server-Side Request Forgery (SSRF) Vulnerability (CVE-2019-17670)