Description
In WordPress before 4.7.3, there is authenticated Cross-Site Scripting (XSS) via Media File Metadata. This is demonstrated by both (1) mishandling of the playlist shortcode in the wp_playlist_shortcode function in wp-includes/media.php and (2) mishandling of meta information in the renderTracks function in wp-includes/js/mediaelement/wp-playlist.js.
Remediation
References
Related Vulnerabilities
Atlassian Jira CVE-2019-20402 Vulnerability (CVE-2019-20402)
Magento Insufficient Verification of Data Authenticity Vulnerability (CVE-2019-8112)
Drupal Cryptographic Issues Vulnerability (CVE-2013-6386)
WordPress Plugin AnyMind Widget Cross-Site Request Forgery (1.1)
Piwigo Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-3790)