WordPress is prone to multiple vulnerabilities, including cross-site scripting and directory traversal vulnerabilities. Exploiting these issues may allow an attacker to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, allowing the attacker to steal cookie-based authentication credentials, or to obtain sensitive information that could aid in further attacks. WordPress version 4.6 is vulnerable.
Update to WordPress version 4.6.1 or latest
WordPress Plugin Fancy Product Designer-WooCommerce Arbitrary File Upload (4.6.8)
WordPress Plugin Photo Gallery, Images, Slider in Rbs Image Gallery Multiple Unspecified Vulnerabilities (1.7.3)
WordPress Plugin Ultimate Member-User Profile, User Registration, Login & Membership Multiple Cross-Site Scripting Vulnerabilities (2.0.27)
WordPress Plugin iQ Block Country Cross-Site Scripting (1.2.11)
WordPress Plugin YouSayToo auto-publishing 'submit' Parameter Cross-Site Scripting (1.0.1)