Description
In WordPress before 4.9.9 and 5.x before 5.0.1, crafted URLs could trigger XSS for certain use cases involving plugins.
Remediation
References
Related Vulnerabilities
Oracle JRE CVE-2017-10293 Vulnerability (CVE-2017-10293)
WordPress Plugin 3D Banner Rotator 'upload.php' Arbitrary File Upload (2.1)
phpMyFAQ Other Vulnerability (CVE-2005-3048)
PHP Integer Overflow or Wraparound Vulnerability (CVE-2015-8387)
WordPress Plugin Interactive SVG Image Map Builder Cross-Site Scripting (1.0)