Description
DOMPurify before 3.2.4 has an incorrect template literal regular expression, sometimes leading to mutation cross-site scripting (mXSS).
Remediation
References
Related Vulnerabilities
ReviveAdserver Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2015-7366)
WordPress Plugin Social Login Lite For WooCommerce Security Bypass (1.6.0)
WordPress Plugin WordPress Download Manager Cross-Site Request Forgery (3.2.12)
WordPress Plugin Wrapper Link Elementor Malicious Code (1.0.3)
WordPress Plugin Titan Anti-spam & Security Cross-Site Scripting (4.1)