Description
In jQuery versions greater than or equal to 1.2 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
Remediation
References
Related Vulnerabilities
Python Other Vulnerability (CVE-2014-9365)
WordPress Plugin iThemes Security (formerly Better WP Security) Cross-Site Scripting (5.6.1)
WordPress Plugin Blue Wrench Video Widget Cross-Site Scripting (2.1.0)
WordPress Plugin Better WordPress reCAPTCHA (with no CAPTCHA reCAPTCHA) Cross-Site Scripting (2.0.3)
WordPress Plugin Spellchecker 'general.php' Local and Remote File Include Vulnerabilities (3.1)