Description
Multiple cross-site scripting (XSS) vulnerabilities in wp-includes/class-wp-theme.php in WordPress before 4.4.1 allow remote attackers to inject arbitrary web script or HTML via a (1) stylesheet name or (2) template name to wp-admin/customize.php.
Remediation
References
Related Vulnerabilities
Oracle Database Server CVE-2020-2515 Vulnerability (CVE-2020-2515)
WordPress Plugin Premium Addons for Elementor Multiple Cross-Site Scripting Vulnerabilities (4.2.7)
WordPress Plugin QIWI payment module for Woocommerce Cross-Site Scripting (0.0.9)
concrete5 Improper Input Validation Vulnerability (CVE-2017-18195)