Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:25683
HistoryJun 15, 2020 - 6:12 a.m.

Cross-Site Scripting(XSS)

2020-06-1506:12:15
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12

EPSS

0.001

Percentile

47.0%

WordPress is vulnerable to cross-site scripting (XSS). The vulnerability exists due to the failure to sanitize the name of the theme folder in /wp-admin on the themes page when the admin uploads the theme.