Description
Cross-site scripting (XSS) vulnerability in wp-includes/wp-db.php in WordPress before 4.2.1 allows remote attackers to inject arbitrary web script or HTML via a long comment that is improperly stored because of limitations on the MySQL TEXT data type.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP Content Copy Protection & No Right Click Security Bypass (3.1.4)
Atlassian Jira URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2021-39112)
Oracle JRE CVE-2013-0426 Vulnerability (CVE-2013-0426)
WordPress Plugin Download Manager PHAR Deserialization (3.2.49)