Lucene search

K
patchstackN/APATCHSTACK:F4DF937630A6D9E65DA69256CE30E79B
HistoryJun 23, 2016 - 12:00 a.m.

WordPress <= 4.5.2 - XSS #1

2016-06-2300:00:00
N/A
patchstack.com
7

0.004 Low

EPSS

Percentile

71.9%

WordPress version 4.5.2 is prone to a cross-site scripting (XSS) vulnerability in the wp_get_attachment_link function in wp-includes/post-template.php. It allows an attacker to inject arbitrary web script or HTML via a crafted attachment name.

Related: http://db.threatpress.com/sysadmin/vulnerabilities/835/

Solution

           Update WordPress. 
CPENameOperatorVersion
wordpressle4.5.2

0.004 Low

EPSS

Percentile

71.9%