Description
jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method. The load method fails to recognize and remove "<script>" HTML tags that contain a whitespace character, i.e: "</script >", which results in the enclosed script logic to be executed.
Remediation
References
Related Vulnerabilities
WordPress Plugin Gallery-Image and Video Gallery with Thumbnails SQL Injection (1.2.0)
MySQL Permissions, Privileges, and Access Controls Vulnerability (CVE-2008-2079)
Atlassian Jira CVE-2021-26081 Vulnerability (CVE-2021-26081)
WordPress Plugin Simple Slideshow Manager Multiple Unspecified Vulnerabilities (2.1)