Description
In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability related to the Customizer exists, involving an invalid customization session.
Remediation
References
Related Vulnerabilities
WordPress Plugin Contact Form 7 Redirect & Thank You Page Cross-Site Request Forgery (1.0.3)
WordPress Plugin AgentPress Broker Listings Cross-Site Scripting (1.0)
MediaWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-4382)
WordPress Plugin Redux Framework Cross-Site Scripting (4.4.17)