Description
Cross-site scripting (XSS) vulnerability in WordPress before 4.3.1 allows remote attackers to inject arbitrary web script or HTML by leveraging the mishandling of unclosed HTML elements during processing of shortcode tags.
Remediation
References
Related Vulnerabilities
Lighttpd Integer Overflow or Wraparound Vulnerability (CVE-2019-11072)
Joomla! Core 3.x.x SQL Injection (3.0.0 - 3.4.6)
WordPress Plugin WP Editor Arbitrary File Upload (1.2.5.3)
WordPress Plugin The Events Calendar Cross-Site Scripting (4.8.1)
Django Improper Validation of Specified Quantity in Input Vulnerability (CVE-2023-41164)