Description
In WordPress before 4.7.3 (wp-admin/js/tags-box.js), there is cross-site scripting (XSS) via taxonomy term names.
Remediation
References
Related Vulnerabilities
MySQL CVE-2018-2846 Vulnerability (CVE-2018-2846)
WordPress Plugin Elementor Website Builder Unspecified Vulnerability (3.0.15)
WordPress Plugin RSS Post Importer Cross-Site Scripting (2.2.1)
OpenSSL Resource Management Errors Vulnerability (CVE-2014-3507)
WordPress Plugin LISL Last-Image Slider TimThumb Arbitrary File Upload (1.0)