Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:4859
HistoryAug 04, 2017 - 6:13 a.m.

Cross-Site Scripting (XSS)

2017-08-0406:13:10
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
4

EPSS

0.003

Percentile

70.8%

WordPress is vulnerable to cross-site scripting (XSS) attacks. The attack exists because the unfiltered_html capability is ignored in the map_meta_cap function of wp-includes/capabilities.php when the multisite feature is used.

EPSS

0.003

Percentile

70.8%