Description
Before WordPress 4.9.5, the version string was not escaped in the get_the_generator function, and could lead to XSS in a generator tag.
Remediation
References
Related Vulnerabilities
Jboss EAP Deserialization of Untrusted Data Vulnerability (CVE-2016-7065)
Jenkins Deserialization of Untrusted Data Vulnerability (CVE-2017-1000355)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-6112)
WordPress Plugin VideoWhisper Video Conference Integration Arbitrary File Upload (4.91.8)