Lucene search

K
patchstackN/APATCHSTACK:B103244988F55A2DB368066013A31C7A
HistoryNov 29, 2017 - 12:00 a.m.

WordPress 1.5.0-4.9 - RSS and Atom Feed Escaping

2017-11-2900:00:00
N/A
patchstack.com
88

EPSS

0.001

Percentile

41.2%

The attributes of enclosures are not correctly escaped in RSS and Atom feeds in wp-includes/feed.php file, which might allow an attacker to exploit XSS via a crafted URL.

Solution

           Update WordPress to v4.9.1.

EPSS

0.001

Percentile

41.2%