Description
WordPress before 5.2.3 allows XSS in media uploads because wp_ajax_upload_attachment is mishandled.
Remediation
References
Related Vulnerabilities
WordPress Authentication Bypass Using an Alternate Path or Channel Vulnerability (CVE-2020-4050)
SharePoint Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-1892)
WordPress Plugin Social Media Tab Remote Code Execution (1.0.9)
WordPress Plugin Google XML Sitemaps Cross-Site Scripting (4.0.8)
MediaWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2021-31549)