Description
jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed.
Remediation
References
Related Vulnerabilities
WordPress Cross-Site Request Forgery (0.70 - 3.6.1)
WordPress Plugin Ultimate Google Analytics Cross-Site Request Forgery (1.6.0)
DataTables Prototype Pollution Vulnerability (CVE-2020-28458)
Oracle Database Server Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-1675)
WordPress Plugin Powie's WHOIS Domain Check Cross-Site Scripting (0.9.31)