Description
Multiple cross-site scripting (XSS) vulnerabilities in wp-includes/class-wp-theme.php in WordPress before 4.4.1 allow remote attackers to inject arbitrary web script or HTML via a (1) stylesheet name or (2) template name to wp-admin/customize.php.
Remediation
References
Related Vulnerabilities
WordPress Plugin Hustle-Pop-Ups, Slide-ins and Email Opt-ins CSV Injection (6.0.7)
MySQL Uncontrolled Resource Consumption Vulnerability (CVE-2020-11080)
Jboss EAP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2013-4112)
XWiki Improper Preservation of Permissions Vulnerability (CVE-2021-21379)
Apache HTTP Server CVE-2013-1862 Vulnerability (CVE-2013-1862)