Description
In jQuery versions greater than or equal to 1.2 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
Remediation
References
Related Vulnerabilities
MySQL CVE-2020-14829 Vulnerability (CVE-2020-14829)
WordPress 4.5.x Multiple Vulnerabilities (4.5 - 4.5.9)
WordPress Plugin WP Import Export Lite Information Disclosure (3.9.15)
WordPress Plugin Advanced Access Manager Unspecified Vulnerability (5.9.8.1)
WordPress Plugin Terillion Reviews Profile Id Cross-Site Scripting (1.1)