Description
WordPress is prone to multiple prototype pollution vulnerabilities. Exploiting these issues could allow an attacker to inject key/value �properties� into JavaScript objects, potentially allowing for execution of arbitrary JavaScript in a user�s session if they can trick that user into clicking a link. WordPress versions 5.7.x ranging from 5.7 and up to (and including) 5.7.5 are vulnerable.
Remediation
Update to WordPress version 5.7.6 or latest
References
https://github.com/BlackFan/client-side-prototype-pollution/blob/master/pp/jquery-query-object.md
https://github.com/WordPress/gutenberg/pull/39365/files
https://wordpress.org/support/wordpress-version/version-5-7-6/
Related Vulnerabilities
WordPress Plugin Featured Post with thumbnail Unspecified Vulnerability (1.4)
WordPress Plugin MF Gig Calendar Cross-Site Scripting (1.1)
Joomla! Core 1.5.x Cross-Site Scripting (1.5.0 - 1.5.10)
WordPress Plugin WordPress Content Slide Multiple Vulnerabilities (1.4.2)
WordPress Plugin UserPro-Community and User Profile Cross-Site Scripting (4.9.23)