Description
In affected versions of WordPress, a cross-site scripting (XSS) vulnerability in the navigation section of Customizer allows JavaScript code to be executed. Exploitation requires an authenticated user. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3, 5.2.6, 5.1.5, 5.0.9, 4.9.14, 4.8.13, 4.7.17, 4.6.18, 4.5.21, 4.4.22, 4.3.23, 4.2.27, 4.1.30, 4.0.30, 3.9.31, 3.8.33, 3.7.33).
Remediation
References
Related Vulnerabilities
Zope Web Application Server Other Vulnerability (CVE-2012-5486)
MySQL CVE-2012-0102 Vulnerability (CVE-2012-0102)
WordPress Plugin Eu Cookie Notice Cross-Site Request Forgery (1.0.6)
WordPress Plugin More Fields Cross-Site Request Forgery (2.1)
WordPress Plugin WooCommerce PDF Invoices & Packing Slips Cross-Site Request Forgery (2.2.6)