Description
In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could modify new comments made by users with greater privileges, possibly causing XSS.
Remediation
References
Related Vulnerabilities
DataTables Prototype Pollution Vulnerability (CVE-2020-28458)
WordPress Plugin YITH WooCommerce Gift Cards Unspecified Vulnerability (2.14.0)
WordPress Plugin BP GTM System Cross-Site Scripting (1.9.5)
WordPress Plugin Affiliate Power-Sales Tracking for Affiliate Marketers Cross-Site Scripting (2.2.0)