Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:5199
HistorySep 29, 2017 - 8:50 a.m.

Cross-site Scripting (XSS)

2017-09-2908:50:11
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14

EPSS

0.004

Percentile

72.8%

WordPress is vulnerable to cross-site scripting (XSS) attacks. The library does not properly handle HTML elements in the oEmbed sandbox before rendering, allowing a malicious user to inject and execute arbitrary webscript.