Description
In WordPress before 4.7.3 (wp-admin/js/tags-box.js), there is cross-site scripting (XSS) via taxonomy term names.
Remediation
References
Related Vulnerabilities
MySQL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-3319)
WordPress Plugin ChimpMate-WordPress MailChimp Assistant Local File Inclusion (1.3.2)
Serendipity Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2017-5476)
WordPress Plugin Widgets on Pages Cross-Site Scripting (1.6.0)
WordPress Plugin Google Doc Embedder Cross-Site Scripting (2.5.18)